GitGuardian has detected exposed database credentials in your repository. This guide will help you fix these security issues.
# Log into your Railway/Database provider
# Change the password for user: postgres
# Update your production environment variables# Run this in Python to generate a new secret key
from django.core.management.utils import get_random_secret_key
print(get_random_secret_key())# Install Vercel CLI
npm i -g vercel
# Set environment variables (replace with your actual values)
vercel env add SECRET_KEY
vercel env add DB_NAME
vercel env add DB_USER
vercel env add DB_PASSWORD
vercel env add DB_HOST
vercel env add DB_PORT
vercel env add ALLOWED_HOSTS
vercel env add CORS_ALLOWED_ORIGINSSet these in your Vercel dashboard under Settings > Environment Variables:
SECRET_KEY=your-new-secret-key-here
DEBUG=False
DB_NAME=railway
DB_USER=postgres
DB_PASSWORD=your-new-password-here
DB_HOST=junction.proxy.rlwy.net
DB_PORT=11448
ALLOWED_HOSTS=your-app.vercel.app,your-domain.com
CORS_ALLOWED_ORIGINS=https://your-frontend.vercel.appCreate a .env file in the Backend directory (DO NOT commit this file):
# Copy .env.example to .env and fill in values
cp .env.example .env
# Edit .env with your local database credentials
SECRET_KEY=your-local-secret-key
DEBUG=True
DB_NAME=lawai_local
DB_USER=postgres
DB_PASSWORD=your-local-password
DB_HOST=localhost
DB_PORT=5432
ALLOWED_HOSTS=localhost,127.0.0.1
CORS_ALLOWED_ORIGINS=http://localhost:3000Backend/Project_Backend/settings.py- Moved sensitive data to environment variablesBackend/vercel.json- Added environment variable referencesBackend/.env.example- Created template for local development.gitignore- Added to ignore sensitive files
.env- Contains actual secretslocal_settings.py- Local overridessecrets.json- Any secrets filecredentials.json- Database credentials
# Rotate database credentials regularly
# Use strong passwords (16+ characters)
# Limit database access to specific IPs
# Enable SSL connections# In production, always set:
DEBUG = False
ALLOWED_HOSTS = ['your-domain.com'] # Specific domains only
SECURE_SSL_REDIRECT = True
SESSION_COOKIE_SECURE = True
CSRF_COOKIE_SECURE = True# Implement rate limiting
# Use CORS properly
# Validate all inputs
# Log security events- Changed database password
- Generated new Django secret key
- Set all environment variables in Vercel
- Verified
.envis in.gitignore - Tested with
DEBUG=False - Checked CORS settings
- Verified ALLOWED_HOSTS
- Test all API endpoints
- Verify environment variables are loaded
- Check logs for any errors
- Run security scan
- Monitor for any issues
If credentials are still exposed:
- Immediately change all passwords
- Rotate API keys and tokens
- Check access logs for unauthorized access
- Update all environment variables
- Force-push cleaned history if needed
For security issues:
- Check Django Security Documentation: https://docs.djangoproject.com/en/5.0/topics/security/
- Vercel Environment Variables: https://vercel.com/docs/concepts/projects/environment-variables
- Railway Database Security: https://docs.railway.app/deploy/databases
# 1. Add .env to gitignore (if not already done)
echo ".env" >> .gitignore
# 2. Remove .env from git if accidentally committed
git rm --cached .env
git commit -m "Remove .env file from tracking"
# 3. Generate new secret key
python -c "from django.core.management.utils import get_random_secret_key; print(get_random_secret_key())"
# 4. Deploy with new variables
vercel --prodRemember: Security is not a one-time setup. Regularly review and update your security configurations!