network icon indicating copy to clipboard operation
network copied to clipboard

Limit who can see / change secrets

Open aeneasr opened this issue 1 year ago • 1 comments

Preflight checklist

Ory Network Project

No response

Describe your problem

Currently, some secrets (e.g. SMTP server and webhook secrets) can be fetched by using the API. Other secrets like the system secret can not be fetched.

Customers have complained that secrets shoold not be visible to everyone who is part of the project.

Describe your ideal solution

  • Make all secrets "save & forget" - i.e. they can not be exported
  • Make some secrets only visible with a special permission / role

Workarounds or alternatives

None

Version

master

Additional Context

Hiding all secrets will make it more challenging to use an Ory Network config in a self-hosted environment.

aeneasr avatar Sep 27 '24 08:09 aeneasr

To authenticate webhooks, HTTP email servers, and probably also secure SMTP, we could offer mTLS. Pretty easy to implement and proven security.

alnr avatar Oct 21 '24 14:10 alnr