0Pricing
Secure Coding & OWASP Top 10 for Backend · درس

إدارة الأسرار وتخزين الإعدادات الآمن

تعلّم كيفية تخزين الأسرار وتدويرها والوصول إليها بأمان حتى لا تؤدي أخطاء الإعداد إلى تسريب بيانات الاعتماد، مع أنماط لمتغيرات البيئة والخزائن وفحص الأسرار.

إدارة الأسرار وتخزين الإعدادات الآمن درس مجاني في Secure Coding & OWASP Top 10 for Backend على CoddyKit. هذا هو الدرس 4 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في Secure Coding & OWASP Top 10 for Backend، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة Secure Coding & OWASP Top 10 for Backend 4 دروس في المجموع.

بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.

The Secrets Problem

Hardcoded passwords, API keys, and tokens are one of the most common security misconfigurations. Once a secret lands in source control, it must be considered compromised forever.

This lesson covers how to keep secrets out of code and store configuration safely.

Never Commit Secrets

The first rule: secrets never live in your repository. Use a .gitignore to exclude files like .env, and prefer injected configuration over baked-in values.

  • No passwords in source code
  • No keys in config files committed to git
  • No secrets in container images

Environment Variables

Environment variables are the simplest way to inject secrets at runtime. The application reads them from the process environment instead of a tracked file.

import os

db_password = os.environ.get('DB_PASSWORD')
if not db_password:
    raise RuntimeError('DB_PASSWORD is not set')

print('Loaded secret of length', len(db_password))

Limits of Env Vars

Env vars are better than hardcoding but have weaknesses: they can leak through crash dumps, child processes, debug endpoints, and logging of the whole environment.

For high-value secrets, prefer a dedicated secrets manager.

Secret Vaults

Tools like HashiCorp Vault, AWS Secrets Manager, and Azure Key Vault store secrets encrypted at rest, control access via fine-grained policies, and provide an audit trail of every read.

  • Centralized storage with access control
  • Automatic encryption at rest and in transit
  • Audit logs of who fetched what and when

Fetching from a Vault

Applications request secrets at startup using a short-lived identity token instead of a static key.

def get_secret(client, path):
    # client is authenticated via a short-lived role token
    response = client.read(path)
    if response is None:
        raise RuntimeError('Secret not found: ' + path)
    return response['data']['value']

# usage: get_secret(vault, 'secret/data/db')

Secret Rotation

Rotation means changing secrets regularly and immediately after suspected exposure. Short-lived, automatically rotated credentials limit the window an attacker can use a stolen key.

Design apps to reload credentials without a full restart so rotation is painless.

Least Privilege for Secrets

Each service should only be able to read the secrets it needs. Scope vault policies and cloud IAM roles tightly so a compromised service cannot harvest unrelated credentials.

Detecting Leaked Secrets

Use secret-scanning tools in CI to block commits that contain credential patterns. Catching a leak before it merges is far cheaper than rotating after exposure.

import re

patterns = [r'AKIA[0-9A-Z]{16}', r'(?i)password\s*=\s*[\'\"]\S+']
line = 'aws_key = AKIAIOSFODNN7EXAMPLE'

for p in patterns:
    if re.search(p, line):
        print('Possible secret detected!')

Encrypting Config at Rest

When config must be stored as files, encrypt them. Tools like SOPS or sealed-secrets let you commit encrypted values safely, decrypting only at deploy time with a managed key.

  • Encrypt before storing
  • Keep the decryption key in a managed KMS
  • Never store the key alongside the data

Auditing Access

Log and review every secret access. Anomalies, like a service reading a secret it never used before, are strong indicators of compromise and feed your monitoring pipeline.

Quick Check

Test your understanding of secrets management.

Recap

You learned to keep secrets out of code, inject them via env vars or a vault, apply rotation and least privilege, scan for leaks in CI, and audit every access. Proper secrets management closes one of the biggest misconfiguration gaps in backend systems.

الأسئلة الشائعة

هل درس «إدارة الأسرار وتخزين الإعدادات الآمن» مجاني؟

نعم — نص درس «إدارة الأسرار وتخزين الإعدادات الآمن» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة Secure Coding & OWASP Top 10 for Backend، انتقل إلى CoddyKit PRO. تتضمن دورة Secure Coding & OWASP Top 10 for Backend 4 دروس في المجموع.

ماذا ستتعلم في «إدارة الأسرار وتخزين الإعدادات الآمن»؟

تعلّم كيفية تخزين الأسرار وتدويرها والوصول إليها بأمان حتى لا تؤدي أخطاء الإعداد إلى تسريب بيانات الاعتماد، مع أنماط لمتغيرات البيئة والخزائن وفحص الأسرار. تتمرن على Secure Coding & OWASP Top 10 for Backend مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.

هل أحتاج إلى خبرة سابقة لأبدأ Secure Coding & OWASP Top 10 for Backend؟

لا تُشترط خبرة سابقة. Secure Coding & OWASP Top 10 for Backend على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 4 من أصل 4.

كم من الوقت يستغرق درس «إدارة الأسرار وتخزين الإعدادات الآمن»؟

معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.

هل يمكنني كتابة وتشغيل أكواد في درس Secure Coding & OWASP Top 10 for Backend هذا؟

نعم. كل درس في Secure Coding & OWASP Top 10 for Backend يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.

جميع الدروس في هذه الدورة

  1. تقوية إعدادات الخادم والتطبيق
  2. إدارة التبعيات والمكتبات بأمان
  3. إدارة التصحيحات وتحديثات البرمجيات
  4. إدارة الأسرار وتخزين الإعدادات الآمن
← العودة إلى Secure Coding & OWASP Top 10 for Backend