I am going through the Async Javascript and HTTP Requests course. I just finished the Film Finder project where we used the fetch API function to retrieve data from a movie database web API ( The Movie Database (TMDB) ( In this lesson, it mentioned keeping the API key we receive after signup a secret. However, the api key is passed in clear text when an asynchronous request is made in Javascript. Anyone using the web app could view this key. How would we prevent someone from stealing this API key in a real-world app?

