Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

163 gps geocoding #165

Open
wants to merge 4 commits into
base: main
Choose a base branch
from
Open

163 gps geocoding #165

wants to merge 4 commits into from

Conversation

cbrody
Copy link
Member

@cbrody cbrody commented Oct 8, 2024

Enable geocoding of new Case studies, minor mods to Facets and Views displays

Copy link

gitguardian bot commented Oct 8, 2024

⚠️ GitGuardian has uncovered 1 secret following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

🔎 Detected hardcoded secret in your pull request
GitGuardian id GitGuardian status Secret Commit Filename
14080871 Triggered Google API Key 42ad07d config/default/geocoder.geocoder_provider.googlemaps.yml View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secret safely. Learn here the best practices.
  3. Revoke and rotate this secret.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

@cbrody cbrody requested a review from stephen-cox October 8, 2024 16:07
@cbrody
Copy link
Member Author

cbrody commented Oct 8, 2024

@stephen-cox do you have a preferred method for deploying secrets such as the API key in this PR?

@stephen-cox
Copy link
Collaborator

@cbrody The easiest option is to use a config override and add the API key to the settings.local.php file on the server. See https://www.drupal.org/docs/drupal-apis/configuration-api/configuration-override-system#s-global-overrides

This doesn't allow us to easily set this on our local dev environments without committing a test key, which will still be flagged as a potential security issue.

If the module supports encrypting keys we can do that with the Key and Encrypt modules, but many don't.

@cbrody cbrody removed the request for review from stephen-cox November 29, 2024 16:11
@cbrody
Copy link
Member Author

cbrody commented Nov 29, 2024

Will refactor using Key module

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants