mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 03:43:11 +00:00
Replace all hardcoded credentials with configuration-injected values:
- SQL Server connection strings -> ${CONNECTION_STRING} env-var placeholders (4 appsettings files)
- SendGrid API keys -> ${SENDGRID_API_KEY} (incl. commented copies in SendMessage.cs)
- JWT signing secret -> ${JWT_SECRET} (3 appsettings files)
- AWS access key pair in UploadFileHp.cs -> DI-injected IAmazonS3 (SDK default credential chain)
- Google Maps API keys in App.razor / Home.razor -> IConfiguration lookup
- Legacy SMTP credentials in SendMessage.cs comments -> placeholders
Add .env.example documenting required environment variables and a
Configuration & Secrets section in BACKEND_ARCHITECTURE.md.
All exposed credentials were rotated 2026-06-05 prior to this scrub.
Source: github-audit-report.md Criticals 1-2 (Agent A4).
Verified: dotnet build 0 errors; secret-pattern grep clean.
27 lines
No EOL
963 B
JSON
27 lines
No EOL
963 B
JSON
{
|
|
"ConnectionStrings": {
|
|
//"DefaultConnection": "Server=DESKTOP-64LC14O\SQLEXPRESS;Database=SeahavenIndustries;TrustServerCertificate=True;Trusted_Connection=True;MultipleActiveResultSets=true",
|
|
|
|
|
|
// Provide the real value via environment variable ConnectionStrings__DefaultConnection or user-secrets.
|
|
// Do NOT commit credentials. This file is committed, so keep only the placeholder here.
|
|
"DefaultConnection": "${CONNECTION_STRING}"
|
|
},
|
|
"Logging": {
|
|
"LogLevel": {
|
|
"Default": "Information",
|
|
"Microsoft.AspNetCore": "Warning"
|
|
}
|
|
},
|
|
"SendGrid": {
|
|
// Provide the real value via environment variable SendGrid__ApiKey or user-secrets.
|
|
"ApiKey": "${SENDGRID_API_KEY}"
|
|
},
|
|
"AllowedHosts": "*",
|
|
"JWT": {
|
|
"ValidAudience": "http://localhost:4200",
|
|
"ValidIssuer": "http://localhost:7195",
|
|
// Provide the real value via environment variable JWT__Secret or user-secrets.
|
|
"Secret": "${JWT_SECRET}"
|
|
}
|
|
} |