diff --git a/rspec-tools/rspec_template/single_language/secrets/rule.adoc b/rspec-tools/rspec_template/single_language/secrets/rule.adoc index 4de72c822a..40427fd7d3 100644 --- a/rspec-tools/rspec_template/single_language/secrets/rule.adoc +++ b/rspec-tools/rspec_template/single_language/secrets/rule.adoc @@ -19,7 +19,7 @@ include::../../../shared_content/secrets/rationale.adoc[] include::../../../shared_content/secrets/impact/generic_impact.adoc[] -// Uncomment the following line, if specifying detailed impacts from below: +// Uncomment the following line, if specifying detailed impacts from below (also make sure to have new lines around the uncommented includes): // include::../../../shared_content/secrets/impact/specific_impact_intro.adoc[] // Secret may allow hosting arbitrary files @@ -88,15 +88,19 @@ include::../../../shared_content/secrets/impact/generic_impact.adoc[] == How to fix it // 1. Revoke leaked secrets + include::../../../shared_content/secrets/fix/revoke.adoc[] // 2. Analyze recent use to identify misuse + include::../../../shared_content/secrets/fix/recent_use.adoc[] // 3. Use a secret vault in the future + include::../../../shared_content/secrets/fix/vault.adoc[] // 4. Never hard-code secrets + include::../../../shared_content/secrets/fix/default.adoc[] // OAuth PKCE is very specific to OAuth 2.0