Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

avoid hardcoded password in config file #4352

Open
wangsenyan opened this issue Nov 25, 2021 · 1 comment
Open

avoid hardcoded password in config file #4352

wangsenyan opened this issue Nov 25, 2021 · 1 comment
Labels

Comments

@wangsenyan
Copy link

Suggestion

Hi,is there any way to avoid hardcoded password in config file or datasource file ?

for example:

i set encrypted password in config file,

when loopback boot, it auto automatic decryption,

So even if my files are leaked, my password is still safe

thanks

@arnaud16571542
Copy link

arnaud16571542 commented Feb 20, 2022

One way to solve this problem is to transmit password through env variables. In that way, no password are stored in your code. Take at dotenvext npm.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants