# API Keys Location Guide - Wellsprings Project

## 🔍 Current Location of API Keys

### 1. LeadSquared API Keys
**File:** `/var/www/html/wellsprings/school/views.py`

**Lines:** 57, 160, 391

**Current Status:** ❌ HARDCODED in URLs

```python
# Line 57, 160, 391
url = "https://api-in21.leadsquared.com/v2/LeadManagement.svc/Lead.Capture?accessKey=u$r4c361c1c755679105a84d6633d4c6dd9&secretKey=301aa26e6a57dae1df02182ae50bfd83c254c41a"
```

**Credentials:**
- Access Key: `u$r4c361c1c755679105a84d6633d4c6dd9`
- Secret Key: `301aa26e6a57dae1df02182ae50bfd83c254c41a`

---

### 2. Sendinblue (Brevo) API Key
**File:** `/var/www/html/wellsprings/school/views.py`

**Line:** 17

```python
configuration.api_key['api-key'] = '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'
```

---

### 3. Database Credentials
**File:** `/var/www/html/wellsprings/wellsprings/settings.py`

**Lines:** 90-99

```python
DATABASES = {
    'default': {
        'ENGINE': 'django.db.backends.mysql',
        'NAME': 'wsa25',
        'USER': 'root',
        'PASSWORD': 'Wsa@sep25@!',
        'HOST': 'localhost',
        'PORT': '',
    }
}
```

---

## ⚠️ Security Issues

1. ❌ All credentials are **hardcoded in source files**
2. ❌ LeadSquared keys repeated **3 times** (hard to update)
3. ❌ Keys likely **committed to Git** (visible in history)
4. ❌ No **.env file** or environment variable usage
5. ❌ Anyone with code access can see credentials

---

## 🛡️ RECOMMENDED: Secure Configuration

### Option 1: Using settings.py (Simple)

**Step 1:** Add to `wellsprings/settings.py`:

```python
# API Keys Configuration
LEADSQUARED_ACCESS_KEY = 'u$r4c361c1c755679105a84d6633d4c6dd9'
LEADSQUARED_SECRET_KEY = '301aa26e6a57dae1df02182ae50bfd83c254c41a'
SENDINBLUE_API_KEY = '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'
```

**Step 2:** Update `school/views.py`:

```python
from django.conf import settings

# Instead of hardcoded URL, use:
url = f"https://api-in21.leadsquared.com/v2/LeadManagement.svc/Lead.Capture?accessKey={settings.LEADSQUARED_ACCESS_KEY}&secretKey={settings.LEADSQUARED_SECRET_KEY}"

# For Sendinblue:
configuration.api_key['api-key'] = settings.SENDINBLUE_API_KEY
```

---

### Option 2: Using .env file (BEST PRACTICE) ⭐

**Step 1:** Install python-decouple:
```bash
pip install python-decouple
```

**Step 2:** Create `.env` file in project root:
```env
# LeadSquared API
LEADSQUARED_ACCESS_KEY=u$r4c361c1c755679105a84d6633d4c6dd9
LEADSQUARED_SECRET_KEY=301aa26e6a57dae1df02182ae50bfd83c254c41a

# Sendinblue API
SENDINBLUE_API_KEY=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

# Database
DB_NAME=wsa25
DB_USER=root
DB_PASSWORD=Wsa@sep25@!
DB_HOST=localhost

# Django
DJANGO_SECRET_KEY=django-insecure-)69zwmpo879^_ja5_m4w$-lkymk$ro0yy#wyh%=fc!lhig5plb
DEBUG=False
```

**Step 3:** Update `wellsprings/settings.py`:
```python
from decouple import config

SECRET_KEY = config('DJANGO_SECRET_KEY')
DEBUG = config('DEBUG', default=False, cast=bool)

# API Keys
LEADSQUARED_ACCESS_KEY = config('LEADSQUARED_ACCESS_KEY')
LEADSQUARED_SECRET_KEY = config('LEADSQUARED_SECRET_KEY')
SENDINBLUE_API_KEY = config('SENDINBLUE_API_KEY')

# Database
DATABASES = {
    'default': {
        'ENGINE': 'django.db.backends.mysql',
        'NAME': config('DB_NAME'),
        'USER': config('DB_USER'),
        'PASSWORD': config('DB_PASSWORD'),
        'HOST': config('DB_HOST'),
        'PORT': '',
    }
}
```

**Step 4:** Update `school/views.py`:
```python
from django.conf import settings

url = f"https://api-in21.leadsquared.com/v2/LeadManagement.svc/Lead.Capture?accessKey={settings.LEADSQUARED_ACCESS_KEY}&secretKey={settings.LEADSQUARED_SECRET_KEY}"

configuration.api_key['api-key'] = settings.SENDINBLUE_API_KEY
```

**Step 5:** Add to `.gitignore`:
```
.env
*.env
```

---

## 📋 Summary

| Component | Current Location | Security Level | Recommendation |
|-----------|------------------|----------------|----------------|
| LeadSquared Keys | views.py (hardcoded) | 🔴 Low | Move to .env |
| Sendinblue Key | views.py (hardcoded) | 🔴 Low | Move to .env |
| Database Password | settings.py (hardcoded) | 🔴 Low | Move to .env |
| Django Secret Key | settings.py (hardcoded) | 🔴 Low | Move to .env |

---

## ✅ Benefits of .env Approach

1. ✅ Keys **NOT in source code**
2. ✅ **NOT committed to Git**
3. ✅ Easy to change per environment (dev/staging/production)
4. ✅ Centralized configuration
5. ✅ Industry standard practice
6. ✅ Better security

---

## 🚀 Quick Migration Steps

1. Create `.env` file with all credentials
2. Install `python-decouple`
3. Update `settings.py` to read from .env
4. Update `views.py` to use settings constants
5. Add `.env` to `.gitignore`
6. Test thoroughly
7. Remove old hardcoded values

---

**Note:** Keep a secure backup of your `.env` file! Never commit it to version control.







