Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove forms that request sensitive information #898

Open
mtrezza opened this issue Aug 13, 2022 · 0 comments
Open

Remove forms that request sensitive information #898

mtrezza opened this issue Aug 13, 2022 · 0 comments
Labels
bounty:$10 Fix this issue and receive a bounty under the Parse Bounty Program. type:docs

Comments

@mtrezza
Copy link
Member

mtrezza commented Aug 13, 2022

Link to section:

https://docs.parseplatform.org/rest/guide/#your-configuration

What is the issue?

I think this is a well-intended feature, but I don't think we should provide it for security reasons.

This feature asks developers to enter their Parse Server URL, master key and client keys on a webform and submit it. Asking that of a developer goes against establishing awareness for good security practice and facilitates phishing. IMO we should never ask a developer to enter this information anywhere, but in fact create awareness about the sensitivity of that data and remind to never share it with anyone outside a project.

The only way such a feature may make sense was if the docs were made part of a Parse Dashboard backend where the user logged into the dashboard already has access to that information and it is merely displayed from the backend data.

Can you propose a solution?

I'm for removing this feature from the docs and just use common placeholders throughout the code.

@mtrezza mtrezza added type:docs bounty:$10 Fix this issue and receive a bounty under the Parse Bounty Program. labels Aug 13, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bounty:$10 Fix this issue and receive a bounty under the Parse Bounty Program. type:docs
Projects
None yet
Development

No branches or pull requests

1 participant