
* SONARTEXT-418 Create rules S7209 to S7402 * SONARTEXT-418 Create rules S7209 to S7402 * SONARTEXT-418 Add PKCE to OAuth2 secrets * SONARTEXT-418 Fix validation
41 lines
945 B
Plaintext
41 lines
945 B
Plaintext
:example_env: DUO_KEYS
|
|
:example_name: duo_keys
|
|
:example_secret: go4ApTzr0XS5WgqPMwB9Sv7tD422XcrNNmIAUDYO
|
|
:secret_type: secret
|
|
|
|
include::../../../shared_content/secrets/description.adoc[]
|
|
|
|
== Why is this an issue?
|
|
|
|
include::../../../shared_content/secrets/rationale.adoc[]
|
|
|
|
=== What is the potential impact?
|
|
|
|
include::../../../shared_content/secrets/impact/generic_impact.adoc[]
|
|
|
|
== How to fix it
|
|
|
|
// 1. Revoke leaked secrets
|
|
|
|
include::../../../shared_content/secrets/fix/revoke.adoc[]
|
|
|
|
// 2. Analyze recent use to identify misuse
|
|
|
|
include::../../../shared_content/secrets/fix/recent_use.adoc[]
|
|
|
|
// 3. Use a secret vault in the future
|
|
|
|
include::../../../shared_content/secrets/fix/vault.adoc[]
|
|
|
|
// 4. Never hard-code secrets
|
|
|
|
include::../../../shared_content/secrets/fix/default.adoc[]
|
|
|
|
=== Code examples
|
|
|
|
include::../../../shared_content/secrets/examples.adoc[]
|
|
|
|
== Resources
|
|
|
|
include::../../../shared_content/secrets/resources/standards.adoc[]
|