6 ms·
Show HN: I built an open source event-management system
- graystevens 8y agoLooks like you committed a .env file previously with some semi-private details contained within it, plus you’ve hardcoded some Cloudinary API credentials. You may want to rotate them before they’re abused by someone. Edit: oh and some database credentials & getstream.io api credentials
- rsyring 8y agoIf anyone wants to keep secrets in a repo, git-crypt is your friend: https://www.agwa.name/projects/git-crypt/ https://www.agwa.name/projects/git-crypt/
- iyanuashiri 8y agoThanks. Checking it out
- solox3 8y agoOld commits are still showing the credentials. Recommend following this guide to erase your .env from all commits. https://help.github.com/articles/removing-sensitive-data-from-a-repository/ https://help.github.com/articles/removing-sensitive-data-fro...
- Selfcommit 8y agoBlackBox is also great for this purpose: https://github.com/StackExchange/blackbox https://github.com/StackExchange/blackbox
- rasjani 8y agoAlbeit I havent made any effort to try to fix it - its a bit hard to compile on Windows.
- iyanuashiri 8y agoThank you for this. I will do that ASAP
- dwightgunning 8y agoJust a heads up (since I work at getstream.io) that you can easily and quickly rotate the Stream app key/secret via the dashboard. Feel free to contact our support or myself directly - dwight@getstream.io - if you need a hand.
- mynewtb 8y agoDo you have no process ready to rotate a user's exposed credentials? It's what I would expect from any service provider once they become aware of an exposure.
- patrickbolle 8y agoIsn't this exactly what he explained? The user has a easy toggle on their dashboard to rotate credentials - and if he needs a hand with it, contact their support for some help.
- detaro 8y agoI think the parents question was why they wait for the customer to do something instead of blocking/rotating the compromised credentials once they became aware of their existence. E.g. I remember reading that Amazon even scans Github for AWS credentials proactively now, since this happened all the time.
- badestrand 8y agoObviously they don't want to break their customer's production system without asking.
- e12e 8y ago
- tschellenbach 8y agoFounder of Stream here. I recommend that you rotate your API credentials. It's easy to do that in the dashboard.
- pr0tocol_7 8y agomade a little tool to catch these things https://github.com/zricethezav/gitleaks https://github.com/zricethezav/gitleaks. working on a CI version of it right now as well. gotta protect those credentials. edit: ci version here - https://github.com/zricethezav/gitleaks-ci https://github.com/zricethezav/gitleaks-ci. work in progress, trying to add readme and instructions tonight. Also if anyone is interested in making gitleaks-ci into a paid github app... hmu
- ezekg 8y agoThis is very cool! I built something very similar about a year back [0] -- yours looks like it supports some things that mine doesn't but that I've been wanting to add, such as providing the commit hash of the offending commit, which isn't something mine does due to the git diff parsing package I'm using. [0]: https://github.com/ezekg/git-hound https://github.com/ezekg/git-hound
- timmytwotime 8y agoDjango is a great tool for stuff like this. Well done.
- xkbd 8y agoGreat stuff, Iyanu. You just need to perfect the UI.
- spartanatreyu 8y agoI suggest the OP watch this as an example of improving UI, "Refactoring UI: Bad About": https://www.youtube.com/watch?v=S6-q5BheEYU https://www.youtube.com/watch?v=S6-q5BheEYU
- Walkman 8y agoWhy on earth is this on front page?
- stronglikedan 8y agoBecause someone submitted it to HN, and then the HN community found it interesting enough to vote it up.
- segmondy 8y agoBecause people can show their side projects here. You might be really advanced and not impressed, that's fine. There's always that set of folks who are never impressed. I wish to see more Show HN. I like to see more folks building and less talking.
- Walkman 8y agoI'm not saying people should not show projects or doesn't belong here. I really like "Show HN" myself, but why did this particular project made to HN front page is what I don't understand.
- known 8y agoLooks good; Needs refined UI
- chiefalchemist 8y agoMaybe it's wise to split the project into two: the backend API (service) and the frontend UI / UX? This way, if you're ultimately only interested in the service you're not dragging around the UI stuff (even if you're not using it). Maybe?
- stevekemp 8y agoMinor bug report: Edit your profile. Upload a non-image file. Enjoy the backtrace. (Only discovered because uploading an image seems to be mandatory..)
- wmichelin 8y agoOnly after signup too :|
- wehadfun 8y agoWould like a public test account to play around with it. Don't feel like signing up.
- wmichelin 8y agoAttention! Do not sign up! Everyone's information is public on there with autoincrementing ID's. I am not sure if this is intended, but I didn't realize my information would be public.