Skip to content

How to not have security violation in handling of S3 AWS keys? #102

Open
@invictus2010

Description

@invictus2010

The default installation guide for notea has the user put their AWS keys in the .env file, host it on Github, and then deploy to Vercel.

This is a huge security violation since the .env file can be read, leaving the account subsequently pwned.

Am I missing something? I very well could be, since I'm a newbie at hosting things like this.

Metadata

Metadata

Assignees

No one assigned

    Labels

    questionFurther information is requested

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions