Security and integration notes
Key considerations for API keys, browser-visible tile credentials, geolocation and CSV handling.
Google browser API key
A browser key is visible to site visitors by design. Protect it with appropriate Google Cloud referrer and API restrictions rather than attempting to hide it in front-end JavaScript.
Custom XYZ tokens
Any credential embedded in a browser tile URL is visible to visitors. Use only tokens designed for client-side use.
Geolocation
Near Me uses browser permission and local distance calculation. Velox does not persist visitor coordinates.
CSV
The import/export workflow includes validation and spreadsheet-injection protection. Administrators should still treat bulk files as data inputs requiring review.
External services
Site owners are responsible for provider terms, notices, attribution and applicable privacy obligations.
