Giter Site home page Giter Site logo

one question about security about phpdotenv HOT 3 CLOSED

vlucas avatar vlucas commented on May 2, 2024
one question about security

from phpdotenv.

Comments (3)

vlucas avatar vlucas commented on May 2, 2024

Typically, your .env file will be below your web root, so it will never be web-accessible. If it is web accessible, you will have to take extra steps to ensure it is protected with .htaccess of nginx configs, etc.

from phpdotenv.

vlucas avatar vlucas commented on May 2, 2024

Also - In the ideal setup, your .env file itself will never be deployed with your project - the idea is that on the production servers, your environment variables will be already loaded and ready to go through some other config method. So really, dotenv itself and the file parsing step should really only ever be done during development.

from phpdotenv.

DanielFallon avatar DanielFallon commented on May 2, 2024

@vlucas could you go ahead and make this a bit more explicit?

It was obvious for me that this was true, but I just took over a project where a .env file was being used in production and was publicly exposed on the interwebz

Thanks, and looks like a great project!
DJF

from phpdotenv.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.