{"id":245,"date":"2019-11-01T13:54:34","date_gmt":"2019-11-01T13:54:34","guid":{"rendered":"https:\/\/sdf-docs.mansystems.com\/docs\/acr-rules\/security\/sensitive-constants\/"},"modified":"2021-07-30T09:09:53","modified_gmt":"2021-07-30T09:09:53","slug":"sensitiveconstant","status":"publish","type":"docs","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/sensitiveconstant","title":{"rendered":"Constants should not be used for sensitive information"},"content":{"rendered":"\n<p>Sensitive information such as passwords or API keys should be stored safely especially if the constant is made available for use in the client. The alternative would be to store sensitive data as encrypted in an entity with no access rules.<\/p>\n\n\n\n<p>To determine if a constant is sensitive ACR checks if the constant name contains a sensitive keyword such as <em>password <\/em>or <em>key<\/em>. The list of sensitive keywords is configurable e.g. &#8220;<em>password,key<\/em>&#8220;. Not case sensitive.<\/p>\n\n\n\n<p><strong>Noncompliant example:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"504\" height=\"378\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-42.png\" alt=\"\" class=\"wp-image-950\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-42.png 504w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-42-480x360.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 504px, 100vw\" \/><\/figure>\n\n\n\n<p><strong>Compliant example:<\/strong><\/p>\n\n\n\n<p>Sensitive information is stored in the database or in some other way<\/p>\n","protected":false},"featured_media":0,"parent":96,"menu_order":24,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"class_list":["post-245","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/245"}],"collection":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=245"}],"version-history":[{"count":7,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/245\/revisions"}],"predecessor-version":[{"id":1318,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/245\/revisions\/1318"}],"up":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/96"}],"next":[{"title":"The default administrator name should be changed","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/renamemxadmin","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/241"}],"prev":[{"title":"Published Rest and Web services should require authentication","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/publishedserviceauthentication","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1369"}],"wp:attachment":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=245"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdoc_tag&post=245"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}