#cesperian

1 messages · Page 1 of 1 (latest)

frozen brookBOT
unborn kayak
#

that...is a handle for the win. Nice

chrome vine
#

Your API secret key is what you never want to expose

unborn kayak
#

ya. The docs state that client_secret is supposed to be more or less treated as sensitive... id: {bsonType: 'string'},

#

whoops. wait..

#

but the same is not for the id?...

chrome vine
#

So it shouldn't be logged or stored, that's true

#

But you have to expose it to the customer who is paying

#

API object id's aren't sensitive at all

#

In fact, folks share API object id's in Discord all the time so we can look into things for them

unborn kayak
#

ok, that's really what i was trying to find out

#

really

#

hm. ok

chrome vine
#

Yeah

#

Never share your API key anywhere though

#

Even the test one

unborn kayak
#

maybe everybody on discord is creating security breaches for their respective companies

#

lol. ok all good to know

chrome vine
#

No API id's aren't sensitive and you can't do anything with just an id

unborn kayak
#

gotcha

unborn kayak
#

gotcha

#

ok, cool. Thanks for the insight : )