Skip to content

Use Solidus' preference store for API keys #138

@tvdeyen

Description

@tvdeyen

To ensure "compliance" in this gem with OWASP we could use ActiveRecord's encrypted column feature.

Ideally we would use Solidus build in preference store mechanisms that allows to omit the database completely and store the secrets in the ENV. And in order to still support the feature to add the credentials in the admin we could use the encrypted_string preference value type.

/cc @fthobe @kennyadsl

Originally posted by @tvdeyen in #127 (comment)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions