diff --git a/kachow-patches/vesper-api-gateway/Hardcoded-API-keys-found-in-configuration-files-.patch.ts b/kachow-patches/vesper-api-gateway/Hardcoded-API-keys-found-in-configuration-files-.patch.ts new file mode 100644 index 0000000..c126d83 --- /dev/null +++ b/kachow-patches/vesper-api-gateway/Hardcoded-API-keys-found-in-configuration-files-.patch.ts @@ -0,0 +1,16 @@ +/** + * KA-CHOW Auto-Patch + * Issue: Hardcoded API keys found in configuration files. + * Service: vesper-api-gateway + * + * The code was modified to replace the hardcoded API key with a dynamic retrieval using os.getenv('API_KEY'). This change enhances security by ensuring that sensitive information like API keys are not stored directly in the codebase, reducing the risk of accidental exposure. By using environment variables, the API key can be managed securely outside the codebase. + */ + +import os + +class VesperApiGateway: + def __init__(self): + self.api_key = os.getenv('API_KEY') + + def get_api_key(self): + return self.api_key \ No newline at end of file