Shopify API证书暴露
我收到了Shopify的电子邮件,例如:
这是Shopify的合作伙伴治理团队。 我们要求您,
当我们的安全团队发现公共/草案应用程序S ** y的秘密API凭证已在以下公共存储库中暴露时: 我们要求您,我们要求您以您要求您通过a)结束上述曝光来消除此漏洞,b)通过重新创建具有新凭据的新版本并删除暴露的应用程序来解决脆弱的应用程序
,因此我必须删除Shopify应用程序,或者如果我只删除该仓库,就可以了吗? 由于我不想删除旧应用,因为在Shopify应用程序中获取某些点的访问,但这需要太多时间。
I received email from Shopify like :
This is Shopify’s Partner Governance team. We are reaching out as our security team discovered that secret API credentials for the Public/Draft app S**y have been exposed in the following public repository:
We require that you eliminate this vulnerability by a) closing the above exposure, and b) address the vulnerable app by re-creating a new version of the app with new credentials and deleting the exposed app
So, Do I have to delete the Shopify app or is it fine if I only delete that repo?
As I don't want to remove old app because getting an access of some points in Shopify app but it will take too much time.
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
您应该遵循他们在说什么。您无需删除该应用程序。
yuo从存储库中删除凭据(请记住,不足以仅删除文件并推动,因为它仍然会在git历史记录中 - 在此处检查如何从git历史记录中删除文件?)
您进入应用程序设置shopify.dev并重新创建您的API秘密。
You should follow what they are saying. You don't need to delete the app.
Yuo remove the credentials from the repository (keep in mind that is not sufficient to just remove the file and push because it will still be in the git history - check here How to remove file from Git history?)
You go into the app settings on shopify.dev and recreate your API secrets.