Usage of hard-coded Passport Secret
Overview
Description
Remediation Guidelines
const strategy = new GoogleStrategy({ clientSecret: 'your_hardcoded_secret' }); // unsafe passport.use(strategy);const strategy = new GoogleStrategy({ clientSecret: process.env.GOOGLE_SECRET }); passport.use(strategy);
References
Configuration
Last updated