Why we store the key inside the .env file?
If a hacker manages to access the files on the server, and if he/she could read ALL the files, including all PHP and all .ENV files, then it is irrevelant to store the key separeta inside the .env file because the hacker could read the .env file as well.
So why we don't store the salt inside the PHP, where we generate the hash?
Btw I learning now Codeigniter. (It has a .env file, where these things like that is stored)