Hardcoded API Keys in Production Code

Open
#1,124 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
35/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Stale
Tech stack
dart
Domain
security

Research direction

Start in app/lib/app_config.dart at lines 95-98, 125-128, and 195-198, and review how configuration is supplied for production, staging, and testing. Replace the hardcoded FlagSmith keys with the chosen secure configuration approach, then verify that each environment still receives its key without exposing credentials in source.

Written by the indexing model from the issue text.

Description

Location: app/lib/app_config.dart (lines 95-98, 125-128, 195-198)
Issue: API keys for FlagSmith are hardcoded in source code for all environments:

'apiKey': 'BuzktmbcnMJ77vznU7WhJB'  // Production
'apiKey': 'n6YyxDdrePqwAF49KCYx7S'  // Staging  
'apiKey': 'VtTsMwJwiF69QWFWHGEMKM'  // Testing

Risk: Exposed API keys could lead to unauthorized access to feature flags and potential abuse.
Fix: Move to environment variables or secure key management.

Dominant language
Dart
Stars
9
Forks
5
PR merge metrics
No merged PRs in 30d

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from threefoldtech/grid_connect

All issues in threefoldtech/grid_connect

Similar issues

More Dart issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.