Hard-coded credentials

Hard-coded credentials

Description

Storing passwords, client secrets or API keys directly in source code may allow immediate misuse if the code is exposed.

Potential impact

Service accounts may be compromised, APIs misused, or additional permissions obtained.

Remediation

Protect secrets in a store such as Secret Manager and supply them through runtime environment variables when appropriate. Revoke exposed values, issue replacements and update the applications that use them.

Examples

This example reads an environment variable that has already been supplied. Validate required values and stop startup if they are absent or empty. Restrict access to environment variables and configuration dumps.

Before

php
<?php
$client_secret = "ABigLongSecret";

After

php
<?php
$client_secret = getenv('CLIENT_SECRET');

Explanation:

  • Before: Hard-codes a password, client secret or token in PHP source.
  • After: Reads a secret supplied at runtime. Protect the store and delivery mechanism; revoke exposed values and update consumers with replacements.

References