Skip to content

Conversation

@manosim
Copy link
Member

@manosim manosim commented Aug 1, 2015

Closes #75 .

@manosim manosim changed the title Update dist script Update dist script & Remove client secret key Aug 1, 2015
@manosim manosim added this to the Release 0.0.14 milestone Aug 1, 2015
manosim pushed a commit that referenced this pull request Aug 1, 2015
Update dist script & Remove client secret key
@manosim manosim merged commit b444e11 into master Aug 1, 2015
@manosim manosim deleted the update-dist-script branch August 1, 2015 14:55
@iKlsR
Copy link

iKlsR commented Nov 20, 2016

Did this really change anything, the secrets are still in the repo and they can still be read even after the asar step. I guess ultimately it's a risk we have to make when using oauth clientside.

@manosim
Copy link
Member Author

manosim commented Nov 20, 2016

Hello @iKlsR. This is quite an old PR - The keys that you see in the repository are used only for development - there are separate production keys. You can find more information in the README: https://github.com/manosim/gitify#development

I think we should investigate if there is something we can do to hide them after the asar step.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants