Security best practices strongly suggest keeping secrets out of codebases and filesystems. Commerce Vantiv should support and suggest keeping API credentials out of config files and in environment variables.
Security best practices strongly suggest keeping secrets out of codebases and filesystems. Commerce Vantiv should support and suggest keeping API credentials out of config files and in environment variables.
Comments
Comment #3
steveoliver commentedComment #5
steveoliver commentedValues currently end up in config on settings save. We should make sure they stay out if set in ENV vars.
Comment #7
steveoliver commentedThat should do it.