Remove exposed Auth0 credentials - #1
Draft
jmgasper wants to merge 1 commit into
Draft
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
.env.DEPLOYMENT.mdwith its placeholder form.Why
The archived
backupbranch still contained the reported development Auth0 M2M credentials at its tip. Removing the values prevents continued exposure from current branch content while leaving Git history unchanged as requested.Impact
There are no application logic changes. Deployments using this branch must provide the Auth0 M2M client ID and secret through their environment or deployment configuration.
Root cause
Local development credential values were committed in a tracked environment file, and the client ID was also copied into a deployment example.
Checks
git diff --check: passed with the repository configured to recognize its existing CRLF.envline endings.cdk:npm run buildpassed.submission-watcher-lambda:npm run buildreachestscbut exits because this branch has notsconfig.jsonor TypeScript input files (pre-existing repository baseline).npm lint: unavailable in both relevant packages because neither defines a lint script.