Skip to content

Hardcoded JWT Secret in serverless.yml #68

@beetle-ai

Description

@beetle-ai

ISSUE_NUMBER: GH-38

Description

The JWT_SECRET is hardcoded in the serverless.yml file, which is a security risk.
File: repositories/QuestionBankapi/serverless.yml
Line: 17
Severity: critical

Current Behavior

The JWT secret is exposed in the configuration file.

Expected Behavior

The JWT secret should be stored in a secure environment variable or a secrets management system.

Suggested Fix

Replace the hardcoded secret with an environment variable lookup.

Code Context

JWT_SECRET: flskdjflksdajffds

Additional Notes

This is a critical security vulnerability that could allow attackers to forge JWT tokens.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions