Storing Secrets with DOTENV in Electron Apps

Viewed 1771

I just recently discovered the practice of storing secrets such as API keys using environment variables. And to put the knowledge to some practice, I implemented a project with the Electron framework and stored my database keys in a .env file. It worked well in production and I could establish a connection with my server using something like process.env.key. However, after the app was built, using electron-forge if that matters, the .env file became dereferenced, and thus all keys became undefined.

Since I'm very new to Web app development in general, it confuses me as to how the environment variable can work in a packaged app, if at all. Also, during my search for some Electron tutorial, I came across the fact that installed Apps can still be reverse engineered, exposing the source code. So how can the keys be safe after all? What is the best, or just better practice for handling client connection to a server database?

Please excuse my naivete.

0 Answers
Related