My static site was serving my internal docs
Summary
A 150KB engineering handoff document containing an admin bypass string and an unfixed payment hole was publicly served from the author's production domain. The leak happened because the static hosting exposed the entire build output directory, and dotfiles could be served. A combination of CDN purges and edge caching failed to remove the content until an edge firewall blocked the exposure; the author rotated credentials and fixed a server-side vulnerability, then provided a practical checklist to prevent similar leaks.