# Secrets कैसे leak होते हैं — डेवलपर्स के लिए 1Password और Secrets Hygiene

Source: https://www.geekswithgeeks.com/hi/secrets-hygiene/sh-common-leaks

> आम leak रास्ते पहचानें: Git history, chat, logs, screenshots और shared files।

## आम गलतियाँ

ज़्यादातर leaks हैक नहीं, ग़लतियाँ होती हैं: Git में key commit हो जाना, chat या ticket में password paste करना, CI logs में token छप जाना, `.env` फ़ाइल zip करके mail करना, या dashboard की key दिखाता screenshot।

## Leak पहचानें

नीचे की दोनों lines secret को ऐसी जगह रखती हैं जहाँ वह बाद में पढ़ा जा सकता है। पहली history में हमेशा रहती है, दूसरी साझा logs में पहुँचती है।

```bash
git add .env && git commit -m "add config"
curl -H "Authorization: Bearer $TOKEN" https://api.example.com -v   # -v can print headers
```

## हटाना काफ़ी नहीं

Secret एक बार Git history, chat या log में पहुँच जाए तो मान लें कि उसकी copy बन चुकी है। फ़ाइल हटाने से leak वापस नहीं होता। उपाय है secret को रद्द करना या बदलना।

**Quiz:** एक key commit हुई और अगले commit में हटा दी गई। आपको क्या करना चाहिए?

- [ ] कुछ नहीं, वह चली गई
- [ ] देखें कि कोई नोटिस करता है या नहीं
- [x] Key बदलें, क्योंकि history में वह अब भी है
- [ ] Repository का नाम बदलें

*Answer:* Key बदलें, क्योंकि history में वह अब भी है. पुराने commits में मान रहता है। Key को compromised मानकर बदलें।
