Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.
If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!
API Key Exposure?
-
Are API Keys logged anywhere?
By default they use a userid:password format. That has us wondering if this will expose passwords anywhere, such as in logging, or over the wire.Product: ProGet
Version: 5.0.10
-
It shouldn't, and if you're using SSL then it's encrypted traffic and nothing can "capture" it between... but keep in mind that ProGet is really only providing the server-side API.
If you write a script (or use a tool) that logs all API calls to ProGet, or logs the full call to nuget.exe, then whatever you log is going to be logged.