Skip to content
This repository was archived by the owner on Oct 3, 2025. It is now read-only.
This repository was archived by the owner on Oct 3, 2025. It is now read-only.

Remover SECRET_KEY padrão #244

@rougeth

Description

@rougeth

Enquanto revisava as variáveis de ambiente definidas no Heroku (referência apyb/tarefas#60), percebi que a SECRET_KEY não estava definida. Ao ler o settings.py, vi que essa variável tem um valor padrão definido no código fonte do site.

Precisamos remover o valor padrão do SECRET_KEY.

Warning

Keep this value secret.

Running Django with a known SECRET_KEY defeats many of Django’s security protections, and can lead to privilege escalation and remote code execution vulnerabilities.

Documentação do Django sobre SECRET_KEY: https://docs.djangoproject.com/en/4.0/ref/settings/#std:setting-SECRET_KEY

SECRET_KEY = decouple.config(
'SECRET_KEY',
default='yc!+ii!psza0mi)&vnn_rdsip5ipdyr(0w8hjllxw6p)!wgo1e'
)

Metadata

Metadata

Assignees

No one assigned

    Labels

    BugPrecisa de AjudaIssues que precisam da ajuda da comunidade para serem resolvidas

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions