Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Exposed super secret key #6

Open
Joepock123 opened this issue Oct 22, 2020 · 2 comments
Open

Exposed super secret key #6

Joepock123 opened this issue Oct 22, 2020 · 2 comments
Labels
Code Review question Further information is requested

Comments

@Joepock123
Copy link

Sure you guys are already aware of this, so more of a check in to see how're you thinking of securing this key.

"x-hasura-admin-secret": "secretKey"

@Joepock123 Joepock123 added question Further information is requested Code Review labels Oct 22, 2020
@amberrignell
Copy link
Contributor

Haha yes we'll be changing the secret key and it will be added to request headers through our authentication webhook to avoid it being anywhere client-side

@Joepock123
Copy link
Author

Awesome great to hear!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Code Review question Further information is requested
Projects
None yet
Development

No branches or pull requests

2 participants