matomo-org / matomo

Empowering People Ethically with the leading open source alternative to Google Analytics that gives you full control over your data. Matomo lets you easily collect data from websites & apps and visualise this data and extract insights. Privacy is built-in. Liberating Web Analytics. Star us on Github? +1. And we love Pull Requests!
https://matomo.org/
GNU General Public License v3.0
19.92k stars 2.66k forks source link

Make the password file and the config file two separate files, for security #22764

Open atom-box opened 6 days ago

atom-box commented 6 days ago

When I am on a troubleshooting call or asking in an email: "Please show me what your configuration is", it is not uncommon for the person to inadvertently show me the password to their SQL database.

Is there an advantage to having the name and password stored there in the same file as mundane things like table display settings?

Is there a downside to separating them into two files?