cds-snc / notification-planning

Project planning for GC Notify Team
4 stars 0 forks source link

Detect API keys in templates #1510

Open yaelberger-commits opened 4 months ago

yaelberger-commits commented 4 months ago

Description

As the GC Notify team, we need to be able to scan for and detect API keys in templates, and maybe SIN numbers? so that we can keep GC Notify secure and prevent API keys from being shared where they shouldn't.

Lana Stewart from DTO working on research for scanning feedback for things that need to be removed/redacted

WHY are we building? We had an incident WHAT are we building? Scanning and an alert for API keys found in templates VALUE created by our solution More secure GC Notify

Documentation and Artifacts

Incident report https://docs.google.com/document/d/15a9EKGuFTdPIHfhYPXt8xDg6DHBci451b7bdQB88pDs/edit#heading=h.gjdgxs

Acceptance Criteria

Given some context, when (X) action occurs, then (Y) outcome is achieved

QA Steps