Secrets¶
A secret holds what must never be in the code : keys, passwords, connection strings. Every account gets one at creation, the default secret, and can add more. Code reads them with get secret ; instances pick their connection string from them ; conversions and system APIs use their keys.
| Page | API Security → Secret Management : the secrets of the account, one of them the default. |
| Shape | A TypeScript file which exports an object. common is read by API Maker ; add your own sections next to it. |
| Kept | Encrypted on the server of this environment. Never pushed to Git : each environment has its own values. |
| Another secret | Every request uses the default secret. Your code reads another secret of the account by its name : getSecret(keys, fromSecretName). |
The default secret of a new account¶
The keys of common¶
| Key | Used by |
|---|---|
hashingAlgorithm, nonce |
The hashing conversion of a schema and the hash data API. SHA256 is the algorithm supported. Without nonce, secret is the key. |
encryptionAlgorithm, secret |
The encryption conversion : AES, RC4 or TRIPLEDES. Changing secret means re-encrypting every encrypted value, and re-hashing when there was no nonce. |
encryptionAlgorithmFETransfer, secretFETransfer |
The encrypt and decrypt APIs, the encrypted payloads and the encrypted answers. This is the key you give to your apps. |
feTransferDataValidityInSeconds |
How old an encrypted payload may be. |
apiUserPasswords |
Passwords an API user reads by path (common.apiUserPasswords.default), so the password is not in Git. |
connectionString |
The list offered by the instance form. Any key of the secret can hold one ; this section is a convention. |
authProviders |
The names of the auth providers every API needs by default. Absent : only the API user token. The settings of an API, a table or a database override it. |
multiTenant |
The tenants tables of multi-tenant instances. |
Your own keys¶
Read them from code
const apiKey = await g.sys.system.getSecret('stripe.apiKey');
const [ key, cs ] = await g.sys.system.getSecret([ 'stripe.apiKey', 'common.connectionString.mysql_8' ]);
- Add sections freely :
stripe: { apiKey: '…' }. A path with dots reaches any key. - A team keeps one secret per environment with the same keys and other values : the code does not change between a laptop and production.