Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remover SECRET_KEY padrão #244

Open
rougeth opened this issue May 7, 2022 · 0 comments
Open

Remover SECRET_KEY padrão #244

rougeth opened this issue May 7, 2022 · 0 comments
Labels
Bug Precisa de Ajuda Issues que precisam da ajuda da comunidade para serem resolvidas

Comments

@rougeth
Copy link
Member

rougeth commented May 7, 2022

Enquanto revisava as variáveis de ambiente definidas no Heroku (referência apyb/tarefas#60), percebi que a SECRET_KEY não estava definida. Ao ler o settings.py, vi que essa variável tem um valor padrão definido no código fonte do site.

Precisamos remover o valor padrão do SECRET_KEY.

Warning

Keep this value secret.

Running Django with a known SECRET_KEY defeats many of Django’s security protections, and can lead to privilege escalation and remote code execution vulnerabilities.

Documentação do Django sobre SECRET_KEY: https://docs.djangoproject.com/en/4.0/ref/settings/#std:setting-SECRET_KEY

SECRET_KEY = decouple.config(
'SECRET_KEY',
default='yc!+ii!psza0mi)&vnn_rdsip5ipdyr(0w8hjllxw6p)!wgo1e'
)

@rougeth rougeth added Bug Precisa de Ajuda Issues que precisam da ajuda da comunidade para serem resolvidas labels May 7, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Bug Precisa de Ajuda Issues que precisam da ajuda da comunidade para serem resolvidas
Projects
None yet
Development

No branches or pull requests

1 participant