Description
Storing passwords, client secrets or API keys directly in source code may allow immediate misuse if the code is exposed.
Potential impact
Service accounts may be compromised, APIs misused, or additional permissions obtained.
Remediation
Protect secrets in a store such as Secret Manager and supply them through runtime environment variables when appropriate. Revoke exposed values, issue replacements and update the applications that use them.
Examples
This example reads an environment variable that has already been supplied. Validate required values and stop startup if they are absent or empty. Restrict access to environment variables and configuration dumps.
Before
php
<?php
$client_secret = "ABigLongSecret";
After
php
<?php
$client_secret = getenv('CLIENT_SECRET');
Explanation:
- Before: Hard-codes a password, client secret or token in PHP source.
- After: Reads a secret supplied at runtime. Protect the store and delivery mechanism; revoke exposed values and update consumers with replacements.