Skip to content

Bits of .NET

Daily micro-tips for C#, SQL, performance, and scalable backend engineering.

  • Asp.Net Core
  • C#
  • SQL
  • JavaScript
  • CSS
  • About
  • ErcanOPAK.com
  • No Access
  • Privacy Policy
Asp.Net Core

ASP.NET Core: Stop appsettings.json Secrets From Leaking Into Your Git History

- 30.08.26 | 31.08.26 - ErcanOPAK

⚙️ Committed appsettings.json = Exposed Secrets

A connection string or API key hardcoded into appsettings.json and committed to Git isn’t just visible to your team — if the repo is ever made public, forked, or breached, that secret is exposed permanently, and simply deleting it in a later commit does NOT remove it from history.

🐞 The Problem

{
  "ConnectionStrings": {
    "Default": "Server=prod-db;User Id=admin;Password=RealPassword123;"
  }
}
// Committed once, this password now lives in every clone of the
// repo forever, in every commit after it too, even if you
// "remove" it in the next commit.

✅ The Right Setup Going Forward

  • Local development: dotnet user-secrets, stored outside the repo in your user profile, never committed.
  • Production: environment variables or a real secrets manager (Azure Key Vault, AWS Secrets Manager) — never a checked-in file.
  • appsettings.json should only ever contain non-sensitive defaults and placeholders.

🔐 Local Dev With User Secrets

dotnet user-secrets init
dotnet user-secrets set "ConnectionStrings:Default" "Server=...;Password=...;"
# Automatically picked up by IConfiguration in Development -
# stored in your user profile, never touches the repo at all.

🚨 If a Secret Is ALREADY Committed

  • Rotate/change the actual secret FIRST — this is the only step that matters immediately; rewriting history doesn’t un-expose a password that’s already been seen.
  • Removing it in a new commit is not enough — the old commit still has it, and anyone with any clone still has it.
  • Rewriting history (git filter-repo, or GitHub’s own secret-scanning remediation guide) only helps for FUTURE clones; assume every existing clone and any CI cache already has the old value.

The moment a real secret is committed, treat the secret itself as burned — rotating it is the only fix that actually protects you; cleaning up the git history is just good hygiene afterward.

— Backend Architect

Related posts:

ASP.NET Core: Fix Kestrel Ignoring a Request Size Limit You Set in Code

C# Records — Why They Still Beat Classes for Domain Models

.NET Core: Use Entity Framework Core for Database Access

Post Views: 4

Post navigation

SQL Server: Why a Non-SARGable WHERE Clause Silently Ignores Your Index
ASP.NET Core: Fix CORS Errors That Only Happen in Production, Never in Development

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

October 2026
M T W T F S S
 1234
567891011
12131415161718
19202122232425
262728293031  
« Sep    

Most Viewed Posts

  • Get the User Name and Domain Name from an Email Address in SQL (973)
  • How to make theater mode the default for Youtube (952)
  • How to add default value for Entity Framework migrations for DateTime and Bool (939)
  • Get the First and Last Word from a String or Sentence in SQL (847)
  • How to select distinct rows in a datatable in C# (837)
  • How to enable, disable and check if Service Broker is enabled on a database in SQL Server (624)
  • Add Constraint to SQL Table to ensure email contains @ (590)
  • Average of all values in a column that are not zero in SQL (553)
  • How to use Map Mode for Vertical Scroll Mode in Visual Studio (526)
  • Find numbers with more than two decimal places in SQL (468)

Recent Posts

  • CSS: Fix a prefers-color-scheme Media Query That Gets Silently Overridden by a Browser Extension’s Forced Dark Mode
  • Git: Fix a Merge Commit That Silently Drops a File Because Both Branches Deleted It Differently
  • HTML5: Fix a Native Lazy-Loading Image That Never Loads Because It Sits Inside a Hidden Tab Until the User Clicks It
  • The AI Prompt That Traces a Null Reference Exception Back to the Exact Line That First Produced the Null
  • The AI Prompt That Turns a Gym Membership Contract’s Fine Print Into a Plain-English List of Cancellation Steps
  • Photoshop: Fix a Color Profile Mismatch That Makes Printed Output Look Nothing Like What You Saw On Screen
  • WordPress: Fix Search Results That Return Pages From a Theme You Deactivated Months Ago
  • Visual Studio: Fix a Test Project That Builds Fine Alone but Fails to Discover Any Tests After a NuGet Restore
  • ASP.NET Core: Fix a File Upload That Times Out on Slow Connections Only Because Kestrel’s Minimum Data Rate Feature Kicked In
  • JavaScript: Fix an Array Destructuring Default Value That Silently Never Applies Because null Was Passed Instead of Undefined

Most Viewed Posts

  • Get the User Name and Domain Name from an Email Address in SQL (973)
  • How to make theater mode the default for Youtube (952)
  • How to add default value for Entity Framework migrations for DateTime and Bool (939)
  • Get the First and Last Word from a String or Sentence in SQL (847)
  • How to select distinct rows in a datatable in C# (837)

Recent Posts

  • CSS: Fix a prefers-color-scheme Media Query That Gets Silently Overridden by a Browser Extension’s Forced Dark Mode
  • Git: Fix a Merge Commit That Silently Drops a File Because Both Branches Deleted It Differently
  • HTML5: Fix a Native Lazy-Loading Image That Never Loads Because It Sits Inside a Hidden Tab Until the User Clicks It
  • The AI Prompt That Traces a Null Reference Exception Back to the Exact Line That First Produced the Null
  • The AI Prompt That Turns a Gym Membership Contract’s Fine Print Into a Plain-English List of Cancellation Steps

Social

  • ErcanOPAK.com
  • GoodReads
  • LetterBoxD
  • Linkedin
  • The Blog
  • Twitter
© 2026 Bits of .NET | Built with Xblog Plus free WordPress theme by wpthemespace.com