New React Backend Repository
Find a file
Adam Moussa c887d6d9d8 fix(security): remove hardcoded secrets from source
Replace all hardcoded credentials with configuration-injected values:
- SQL Server connection strings -> ${CONNECTION_STRING} env-var placeholders (4 appsettings files)
- SendGrid API keys -> ${SENDGRID_API_KEY} (incl. commented copies in SendMessage.cs)
- JWT signing secret -> ${JWT_SECRET} (3 appsettings files)
- AWS access key pair in UploadFileHp.cs -> DI-injected IAmazonS3 (SDK default credential chain)
- Google Maps API keys in App.razor / Home.razor -> IConfiguration lookup
- Legacy SMTP credentials in SendMessage.cs comments -> placeholders

Add .env.example documenting required environment variables and a
Configuration & Secrets section in BACKEND_ARCHITECTURE.md.

All exposed credentials were rotated 2026-06-05 prior to this scrub.
Source: github-audit-report.md Criticals 1-2 (Agent A4).
Verified: dotnet build 0 errors; secret-pattern grep clean.
2026-06-05 11:56:54 -04:00
Api.SeaHavenIndustries fix(security): remove hardcoded secrets from source 2026-06-05 11:56:54 -04:00
Data.SeaHavenIndustries backend changes 2026-05-14 11:00:12 -05:00
SeaHaven.DataServices backend changes 2026-05-14 11:00:12 -05:00
SeaHaven.Services backend changes 2026-05-14 11:00:12 -05:00
SeaHavenIndustries fix(security): remove hardcoded secrets from source 2026-06-05 11:56:54 -04:00
.env.example fix(security): remove hardcoded secrets from source 2026-06-05 11:56:54 -04:00
.gitattributes Initial commit 2024-09-28 14:58:36 -04:00
.gitignore Add project TODO tracking deferred work items 2026-04-17 13:08:12 -04:00
BACKEND_ARCHITECTURE.md fix(security): remove hardcoded secrets from source 2026-06-05 11:56:54 -04:00
SeaHavenIndustries.sln refactor 2026-04-28 18:55:14 -05:00
TODO.md Update TODO with completed items and vendor portal next steps 2026-04-17 16:33:17 -04:00