Repository navigation
Mark the published reCAPTCHA test keys in the smoke test - #27
Closed
imanimanyara wants to merge 2 commits into
Closed
imanimanyara wants to merge 2 commits into
imanimanyara wants to merge 2 commits into
Conversation
The test-key store and the live smoke test carry Google's documented always-pass reCAPTCHA pair. The value is the feature, so it stays, and each line now ends with ggignore and gitleaks:allow. The provider switching example in the docs used a key-shaped placeholder; it now reads example-key.
|
| GitGuardian id | GitGuardian status | Secret | Commit | Filename | |
|---|---|---|---|---|---|
| 36063431 | Triggered | reCAPTCHA Key | 3f61d10 | src/Credentials/TestKeyCredentialStore.php | View secret |
| 36063431 | Triggered | reCAPTCHA Key | 3f61d10 | src/Credentials/TestKeyCredentialStore.php | View secret |
| 36063431 | Triggered | reCAPTCHA Key | c2ac0c0 | src/Credentials/TestKeyCredentialStore.php | View secret |
| 36063431 | Triggered | reCAPTCHA Key | c2ac0c0 | src/Credentials/TestKeyCredentialStore.php | View secret |
🛠 Guidelines to remediate hardcoded secrets
- Understand the implications of revoking this secret by investigating where it is used in your code.
- Replace and store your secrets safely. Learn here the best practices.
- Revoke and rotate these secrets.
- If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.
To avoid such incidents in the future consider
- following these best practices for managing and storing secrets including API keys and other credentials
- install secret detection on pre-commit to catch secret before it leaves your machine and ease remediation.
🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.
Editing the lines that hold Google's published reCAPTCHA pair puts them in the pull request diff, and the GitGuardian GitHub App, which does not read inline markers, reports them there. The store keeps its existing ignored_matches entry in .gitguardian.yaml; the markers stay on the smoke test and the docs example.
Member
Author
|
Superseded by #28 (docs only; the reCAPTCHA test-key lines are left alone so GitGuardian has nothing to flag). Branch kept. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
tests/Feature/Live/ProviderSmokeTest.php: the two lines carrying Google's published reCAPTCHA v2 test key pair end withggignore gitleaks:allow. The value is the documented always-pass pair and the test depends on it.docs/getting-started.md: the provider-switching example usesexample-keyinstead of a key-shaped0x4AAA.....gitguardian.yamland itsignored_matchesentry are untouched.A first commit also marked the same pair in
src/Credentials/TestKeyCredentialStore.php. That put those lines in the PR diff and the GitGuardian App (incident 36063431, reCAPTCHA Key) flagged them, since it does not read inline markers. That commit is reverted here, sosrc/is unchanged. Clearing that incident for good needs a dashboard secret-pattern exclusion for the exact published value; that is the owner's setting.Secret-scan hygiene, approved by the owner as one PR per repository.
secret_scan.py detectfound no real secrets.Verification
secret_scan.py check --ref HEAD: exit 0, 2 marked as allowed (was 3 dummy findings).BrowserRuntimeTestneeds a browser the sandbox does not have. phpstan, laranail-pint --test, rector --dry-run: clean.