TooAngel / worlddriven

Automatic and well-defined pull request merged based on contribution-based weighted voting
GNU Affero General Public License v3.0
18 stars 14 forks source link

Encrypt the github tokens in the database #197

Closed TooAngel closed 3 years ago

TooAngel commented 4 years ago

The github keys currently are stored in plain text in the database. To make sure these are not accessible if someone gets access to the database, the keys needs to be encrypted with a secret which is available in the application via environment variable.

EANimesha commented 4 years ago

Can I try this?

TooAngel commented 4 years ago

Yeah, sure go ahead.

Let me know if you have any questions.

TooAngel commented 4 years ago

Hey, were you able to make any progress, can I help somehow?

EANimesha commented 4 years ago

Hey, were you able to make any progress, can I help somehow?

couldn't able to make a progress