Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Better secrets handling #18

Open
GregSherman opened this issue Sep 8, 2024 · 0 comments
Open

Better secrets handling #18

GregSherman opened this issue Sep 8, 2024 · 0 comments

Comments

@GregSherman
Copy link
Collaborator

GregSherman commented Sep 8, 2024

Right now, the JWT are generated by a secret as an env variable generated manually by open SSL. oauth api keys are stored in plaintext in the database.

There should be a service that handles the storing and rotating of the JWT key and api keys.

@GregSherman GregSherman changed the title dynamic jwt secret Better secrets handling Sep 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant