I can't count the amount of SO questions I've had to edit from others posting live API Keys for everything from custom services to AWS.
I can't count the amount of SO questions I've had to edit from others posting live API Keys for everything from custom services to AWS.
Something like giving false confidence to the user. Not the best idea.
Of course, then your secret key checker would need to build that string by concatenating so that it wouldn't set off itself.
A project I maintain, Gitleaks, can easily detect "unique" secrets and does a pretty good job at detecting "generic" secrets too. In this case, the generic gitleaks rule would have caught the secrets [1]. You can see the full rule definition here [2] and how the rule is constructed here [3].
[1] https://regex101.com/r/CLg9TK/1
[2] https://github.com/zricethezav/gitleaks/blob/master/config/g...
[3] https://github.com/zricethezav/gitleaks/blob/master/cmd/gene...
Here is a full explanation if you are interested: https://blog.gitguardian.com/why-detecting-generic-credentia...
https://res.cloudinary.com/da8kiytlc/image/upload/v164614852...
But as mentioned below - Still advised to change your keys for obvious reasons
The only thing you can do is rotating the token/secret.