BackendLesson 4 of 48 min

Secrets and environment variables

Where keys live, how they leak, and what to do the moment one does.

A secret is any value that grants access: a database password, an API key, a signing key. The rule is simple to state and easy to break by accident: secrets never go in your code, because your code goes to places you do not fully control.

Instead they are supplied as environment variables, values handed to your program by whatever starts it. The same build then runs against a test database locally and the real one in production, without any code change and without a secret ever sitting in a file you commit.

When a secret leaks
  1. Rotate first
    Issue a new key and revoke the old one. Do this before anything else.
  2. Then clean up
    Remove it from the code. Note that git history keeps it forever, so deleting the line is not enough.
  3. Then check usage
    Look at logs for use you did not make.

Would this value still be dangerous if a stranger read it?

That is the definition of a secret. If yes, it belongs in environment configuration and never in a file you commit or a bundle you ship.

What to remember

  • Secrets come from the environment, never from code.
  • Anything in the client bundle is public forever.
  • On a leak, revoke first; cleaning up history comes second.

Terms in this lesson

Field notes

Loaded from a deliberately slow source. The lesson above was already readable while this was still travelling. That is streaming, and it is the same trick a chat interface uses.

The URL that read everyone’s invoices

An invoice page checked that you were logged in and then loaded whatever id was in the address. Changing the number showed somebody else’s invoice. It was found by a customer who mistyped, not by a review.

Classic IDOR, still extremely common

The key in the client bundle

An API key was placed behind the public environment prefix so it would be readable from the frontend. It worked. It was also visible to every visitor, and was being used by strangers within a week.

Scraped from a public bundle

resolved in 901ms · region iad1

Hide field notes toggles a search param the loader reads. With it off, the slow promise is never created, so nothing streams.