shoc-backend/.env.example
Adam Moussa c887d6d9d8 fix(security): remove hardcoded secrets from source
Replace all hardcoded credentials with configuration-injected values:
- SQL Server connection strings -> ${CONNECTION_STRING} env-var placeholders (4 appsettings files)
- SendGrid API keys -> ${SENDGRID_API_KEY} (incl. commented copies in SendMessage.cs)
- JWT signing secret -> ${JWT_SECRET} (3 appsettings files)
- AWS access key pair in UploadFileHp.cs -> DI-injected IAmazonS3 (SDK default credential chain)
- Google Maps API keys in App.razor / Home.razor -> IConfiguration lookup
- Legacy SMTP credentials in SendMessage.cs comments -> placeholders

Add .env.example documenting required environment variables and a
Configuration & Secrets section in BACKEND_ARCHITECTURE.md.

All exposed credentials were rotated 2026-06-05 prior to this scrub.
Source: github-audit-report.md Criticals 1-2 (Agent A4).
Verified: dotnet build 0 errors; secret-pattern grep clean.
2026-06-05 11:56:54 -04:00

34 lines
1.6 KiB
Text

# Sea Haven Industries — shoc-backend required configuration
#
# This file documents the secrets that used to be hardcoded in appsettings*.json
# and source files. Copy the values into one of the supported configuration sources;
# do NOT commit real values.
#
# .NET resolves configuration in this order (later wins):
# 1. appsettings.json / appsettings.{Environment}.json (committed — placeholders only)
# 2. User Secrets (local dev): dotnet user-secrets set "Key:Sub" "value"
# 3. Environment variables (use "__" as the section separator)
#
# Environment-variable form is shown below. In AWS Elastic Beanstalk these map to
# environment properties; locally you can export them or use dotnet user-secrets.
#
# AWS credentials for the S3 client are NOT listed here on purpose: UploadFileHp now
# uses the AWS SDK default credential chain (env AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY,
# the shared profile/SSO, or the EC2/ECS instance role). Prefer an instance role in prod.
# --- SQL Server connection string (Api.SeaHavenIndustries + SeaHavenIndustries) ---
ConnectionStrings__DefaultConnection=Server=<host>;Initial Catalog=<db>;User Id=<user>;Password=<password>;MultipleActiveResultSets=true
# --- SendGrid (transactional email) ---
SendGrid__ApiKey=SG.xxxxxxxxxxxxxxxxxxxxxx
# --- JWT signing secret (Api.SeaHavenIndustries) ---
JWT__Secret=<a-long-random-secret>
# --- Google Maps / Places API key (SeaHavenIndustries Blazor app) ---
GoogleMaps__ApiKey=AIzaSyXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
# --- AWS S3 (optional; prefer instance role / SSO over static keys) ---
# AWS_ACCESS_KEY_ID=
# AWS_SECRET_ACCESS_KEY=
# AWS_REGION=us-east-2