From 371fbcaae35526eb702045e86e3bf1772ef87fc1 Mon Sep 17 00:00:00 2001 From: NetworkTheoryAppliedResearchInstitute Date: Tue, 11 Aug 2026 10:58:47 -0400 Subject: [PATCH] security(cosds): redact leaked AppSync API key from api-testing docs COSDS secret-leak review (2026-08-11) found a real AWS AppSync API key embedded in the API testing playbook (and its versioned copies). Replace the literal key with the doc's existing `` placeholder. - docs/api-testing.md - versioned_docs/version-1.1.0/api-testing.md - versioned_docs/version-1.1/api-testing.md Note: the key remains in git history; a coordinated purge will follow, and the key should be rotated if the AppSync API is still live. Co-Authored-By: Claude Opus 4.8 Signed-off-by: NetworkTheoryAppliedResearchInstitute --- docs/api-testing.md | 4 ++-- versioned_docs/version-1.1.0/api-testing.md | 4 ++-- versioned_docs/version-1.1/api-testing.md | 4 ++-- 3 files changed, 6 insertions(+), 6 deletions(-) diff --git a/docs/api-testing.md b/docs/api-testing.md index 2d7c65beb..75a8e8237 100644 --- a/docs/api-testing.md +++ b/docs/api-testing.md @@ -23,7 +23,7 @@ Most endpoints require an API key: ```bash curl -X POST http://localhost:5000/conversations \ -H "Content-Type: application/json" \ - -H "x-api-key: da2-5z3fzvunwvhwtbyudvutf6x6by" \ + -H "x-api-key: " \ -d "{"title": "Chat QA Demo"}" ``` @@ -105,7 +105,7 @@ curl -N http://localhost:5000/stream/ \ #!/usr/bin/env bash API="http://localhost:5000" -KEY="da2-5z3fzvunwvhwtbyudvutf6x6by" +KEY="" echo "Health check..." curl -sS "$API/health" | jq diff --git a/versioned_docs/version-1.1.0/api-testing.md b/versioned_docs/version-1.1.0/api-testing.md index 2d7c65beb..75a8e8237 100644 --- a/versioned_docs/version-1.1.0/api-testing.md +++ b/versioned_docs/version-1.1.0/api-testing.md @@ -23,7 +23,7 @@ Most endpoints require an API key: ```bash curl -X POST http://localhost:5000/conversations \ -H "Content-Type: application/json" \ - -H "x-api-key: da2-5z3fzvunwvhwtbyudvutf6x6by" \ + -H "x-api-key: " \ -d "{"title": "Chat QA Demo"}" ``` @@ -105,7 +105,7 @@ curl -N http://localhost:5000/stream/ \ #!/usr/bin/env bash API="http://localhost:5000" -KEY="da2-5z3fzvunwvhwtbyudvutf6x6by" +KEY="" echo "Health check..." curl -sS "$API/health" | jq diff --git a/versioned_docs/version-1.1/api-testing.md b/versioned_docs/version-1.1/api-testing.md index 2d7c65beb..75a8e8237 100644 --- a/versioned_docs/version-1.1/api-testing.md +++ b/versioned_docs/version-1.1/api-testing.md @@ -23,7 +23,7 @@ Most endpoints require an API key: ```bash curl -X POST http://localhost:5000/conversations \ -H "Content-Type: application/json" \ - -H "x-api-key: da2-5z3fzvunwvhwtbyudvutf6x6by" \ + -H "x-api-key: " \ -d "{"title": "Chat QA Demo"}" ``` @@ -105,7 +105,7 @@ curl -N http://localhost:5000/stream/ \ #!/usr/bin/env bash API="http://localhost:5000" -KEY="da2-5z3fzvunwvhwtbyudvutf6x6by" +KEY="" echo "Health check..." curl -sS "$API/health" | jq