> For the complete documentation index, see [llms.txt](https://docs.sec1.io/user-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.sec1.io/user-docs/4-sast/3-javascript/usage-of-hard-coded-passport-secret.md).

# Usage of hard-coded Passport Secret

## Overview

* **Rule ID**: `javascript_third_parties_passport_hardcoded_secret`
* **Applicable Languages**: Javascript
* **Weakness ID**: CWE-798

## Description

Storing secrets directly in your code, such as a passport authentication secret, is insecure. This approach makes your application susceptible to attacks if the codebase is exposed.

## Remediation Guidelines

* **Avoid** hard-coding secrets in your application code. Hard-coding makes sensitive information readily accessible to anyone who can view the code.

  ```javascript
  const strategy = new GoogleStrategy({ clientSecret: 'your_hardcoded_secret' }); // unsafe
  passport.use(strategy);

  ```
* **Use environment variables** to manage secrets securely. This approach keeps sensitive information out of your codebase and makes it harder for unauthorized users to access.

  ```javascript
  const strategy = new GoogleStrategy({ clientSecret: process.env.GOOGLE_SECRET });
  passport.use(strategy);

  ```

## References

* [**OWASP hardcoded passwords**](https://owasp.org/www-community/vulnerabilities/Use_of_hard-coded_password)
* [**CWE-798: Use of Hard-coded Credentials**](https://cwe.mitre.org/data/definitions/798.html)
* [**OWASP Top 10: A07:2021 - Identification and Authentication Failures**](https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/)

## Configuration

To omit this rule during a scan, and to provide you with continuous 24/7 code-level scanning, you can employ our [**SAST TOOL**](https://scopy.sec1.io/login)
