Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

should add a warning that ghapi.json might contain sensitive info and should not be made available to public #7

Open
pajtai opened this issue Jul 28, 2014 · 2 comments

Comments

@pajtai
Copy link
Contributor

pajtai commented Jul 28, 2014

after going through gh jump, a ghapi.json file was created - this had my mongolab u/p - also if amazon engine is used, assuming it will have that

would be a good idea to create a written warning, and might be a good idea to auto generate a .gitignore file w ghapi.json included if a .git is detected

@travism
Copy link
Contributor

travism commented Jul 28, 2014

Yeah, maybe a global warning for all commands would do the trick. I am not sure I want to dictate how they manage their gitignore but I completely agree with the warning.

@pajtai
Copy link
Contributor Author

pajtai commented Jul 28, 2014

I'm all for warning with a question

The ghapi.json we created for you has sensitive information in it.
It looks like this is a git project.

Would you like ghapi.json added to your .gitignore?
> Yes
   No

Just from playing around with Sails, Yeoman, and other CLI helpers, it seems that the more work they do for you the more fun they are to use. I don't want it to do a bunch of stuff for me I don't know about, but if it's doing stuff I'd just have to remember to do later anyway... and I can opt out if I want... that seems like good ux.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants