Skip to content
This page View Markdown Open in ChatGPT Open in Claude

Secrets

A secret holds what must never be in the code : keys, passwords, connection strings. Every account gets one at creation, the default secret, and can add more. Code reads them with get secret ; instances pick their connection string from them ; conversions and system APIs use their keys.

Page API Security → Secret Management : the secrets of the account, one of them the default.
Shape A TypeScript file which exports an object. common is read by API Maker ; add your own sections next to it.
Kept Encrypted on the server of this environment. Never pushed to Git : each environment has its own values.
Another secret Every request uses the default secret. Your code reads another secret of the account by its name : getSecret(keys, fromSecretName).

The default secret of a new account

import * as T from 'types';

let Secret: T.ISecretType | any = {
    common: <T.ISecretTypeCommon>{
        hashingAlgorithm: 'SHA256',              // the hashing conversion and the hash data API
        nonce: '85491cec-…',                     // key of the hashes ; without it, secret is used

        encryptionAlgorithm: 'AES',              // the encryption conversion of the schemas
        secret: '1eaaca38-…',                    // never change it once data is encrypted with it

        encryptionAlgorithmFETransfer: 'AES',    // encrypt and decrypt data system APIs
        secretFETransfer: '78e493ee-…',          // shared with your frontend or mobile app
        feTransferDataValidityInSeconds: 300,    // an encrypted payload older than this is refused

        apiUserPasswords: {                      // API users can read their password from a path of the secret
            default: '12345',
        },

        connectionString: {                      // offered when you add an instance
            mongodb: 'mongodb://your_username:your_password@server_ip:27017/?authSource=admin&replicaSet=rs0&directConnection=true',
            mysql_8: 'mysql://your_username:your_password@server_ip:server_port?multipleStatements=true',
            mariadb: 'mariadb://your_username:your_password@server_ip:server_port?multipleStatements=true',
            sqlServer: 'Server=server_ip;User Id=user_id;Password=your_password;Trusted_Connection=True;TrustServerCertificate=True;',
            postgresql: 'postgresql://your_username:your_password@server_ip:server_port',
            oracle: 'server_ip:server_port/oracle_process_name',
            oracle_username: 'your_username',
            oracle_password: 'your_password',
        },

        // authProviders: <string[]>[],           // the auth providers every API needs unless its settings say otherwise
    },
};
module.exports = Secret;

The keys of common

Key Used by
hashingAlgorithm, nonce The hashing conversion of a schema and the hash data API. SHA256 is the algorithm supported. Without nonce, secret is the key.
encryptionAlgorithm, secret The encryption conversion : AES, RC4 or TRIPLEDES. Changing secret means re-encrypting every encrypted value, and re-hashing when there was no nonce.
encryptionAlgorithmFETransfer, secretFETransfer The encrypt and decrypt APIs, the encrypted payloads and the encrypted answers. This is the key you give to your apps.
feTransferDataValidityInSeconds How old an encrypted payload may be.
apiUserPasswords Passwords an API user reads by path (common.apiUserPasswords.default), so the password is not in Git.
connectionString The list offered by the instance form. Any key of the secret can hold one ; this section is a convention.
authProviders The names of the auth providers every API needs by default. Absent : only the API user token. The settings of an API, a table or a database override it.
multiTenant The tenants tables of multi-tenant instances.

Your own keys

Read them from code
const apiKey = await g.sys.system.getSecret('stripe.apiKey');
const [ key, cs ] = await g.sys.system.getSecret([ 'stripe.apiKey', 'common.connectionString.mysql_8' ]);
  • Add sections freely : stripe: { apiKey: '…' }. A path with dots reaches any key.
  • A team keeps one secret per environment with the same keys and other values : the code does not change between a laptop and production.