3 ms·
isn't this a problem? https://github.com/baicunko/scanyourpdf/blob/master/convertpdf/settings.py#L23 https://github.com/baicunko/scanyourpdf/blob/master/conver
by thebigshane 6y ago
isn't this a problem? https://github.com/baicunko/scanyourpdf/blob/master/convertpdf/settings.py#L23 https://github.com/baicunko/scanyourpdf/blob/master/convertp...
- rozab 6y agoI thought github had hooks for this kind of thing now? I remember it caught a private key I tried to push to a similar django repo (not for a prod site or anything), and that was about 2 years ago
- dewey 6y agoI think this only works for secret keys that have a certain pattern like AWS keys.
- baicunko 6y agoI manually modified the private key on the server before publishing here. Still learning on ENV VARIABLES and I couldn't make them work!
- vmception 6y agohaha this is like those domain name search websites that just automatically register the good sounding domain names for themselves once the user types it in. do you OP! I think it still provides a service, enjoy all the secrets
- kchr 6y agoIf you upload secrets to public sites you're in trouble regardless of whether they claim "secure" hosting or not... And what makes you think the operator has nefarious intent?
- 411111111111111 6y agoYou might want to just switch to a dotenv library. Quick Google for Django yielded https://github.com/jpadilla/django-dotenv https://github.com/jpadilla/django-dotenv
- capableweb 6y agoDotenv libraries are just for dev and other similar environments. In production you should still use normal environment variables (or whatever system you use to load your configuration), as dotenv files stay on the filesystem and sometimes even committed to your SCM.
- deleted 6y ago[deleted]