I am writing a command-line application in Python 3. The app will be run by different users on their local machines. Some parts of the application require to login to a database. I want to give the users the choice to store their credentials or type them in every time.
For storing the credentials (if the users chose so) I want to use a seperate file which is created on the local machine and which is encrypted. For the encryption of the file I need to generate a key.
Now my question: Is it a good idea to store that key needed for encryption and decryption as an environment variable (I want to distribute critical information and not just store them in another file with the app)? What solutions should I consider where to store the key? Are there different environment variables (in terms of safety)?
I am aware, that there is no perfect solution (especially not with a python script which is stored in plain text by itself), but I want to put some effort in thinking this through and not just use .netrc or something like this.
Thank you in advance for some ideas.
Frank