Casting Socialite google_refresh_token #58466
Unanswered
obayesshelton
asked this question in
Q&A
Replies: 1 comment
-
|
I would consider it a best practice against a different threat model (database breaches, leaked backups, SQL injection, compromised DB credentials). Refresh tokens are particularly sensitive, and application-level encryption has minimal overhead. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hi everyone,
I am currently building a platform heavily reliant on the YouTube Data API. We are storing
refresh_tokensto perform background jobs.I know standard advice is "encrypt everything," but I am trying to determine the modern "Best Practice" for Laravel 12 applications running on managed infrastructure (where the DB volume is already encrypted).
My specific question: Is it recommended to add the encrypted cast to the User model in addition to DB encryption?
What is the consensus here?
Beta Was this translation helpful? Give feedback.
All reactions