Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

GOOGLE_OAUTH_SECRET is passed to script as env var and can be retrieved #478

Open
yosefy opened this issue Aug 5, 2021 · 3 comments
Open

Comments

@yosefy
Copy link

yosefy commented Aug 5, 2021

is passed to script as ENV VAR
is it by design?

thanks

@bugy
Copy link
Owner

bugy commented Aug 6, 2021

Hi @yosefy, script server propagates all environment variables from the OS to the running script. So I believe you have GOOGLE_OAUTH_SECRET as your secret in OS, is it correct?

@yosefy
Copy link
Author

yosefy commented Aug 6, 2021 via email

@bugy
Copy link
Owner

bugy commented Aug 6, 2021

Unfortunately, there is no way to hide it :( I would call it a bug (security issue).

@bugy bugy added the bug label Aug 6, 2021
@bugy bugy added the resolved label Nov 5, 2022
@bugy bugy added this to the 1.18.0 milestone Nov 5, 2022
bugy added a commit that referenced this issue Nov 5, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants