Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I see this standard linked here a lot. Did anyone read it though? It only helps with identifying whether a string is a secret, not at all the service or environment where the secret applies.


If any value does not natively support secret token sceme, you can apply secret-token: prefix and then strip it during the usage.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: