Skip to content
This repository was archived by the owner on Oct 3, 2025. It is now read-only.
This repository was archived by the owner on Oct 3, 2025. It is now read-only.

Remover SECRET_KEY padrão #244

Description

@rougeth

Enquanto revisava as variáveis de ambiente definidas no Heroku (referência apyb/tarefas#60), percebi que a SECRET_KEY não estava definida. Ao ler o settings.py, vi que essa variável tem um valor padrão definido no código fonte do site.

Precisamos remover o valor padrão do SECRET_KEY.

Warning

Keep this value secret.

Running Django with a known SECRET_KEY defeats many of Django’s security protections, and can lead to privilege escalation and remote code execution vulnerabilities.

Documentação do Django sobre SECRET_KEY: https://docs.djangoproject.com/en/4.0/ref/settings/#std:setting-SECRET_KEY

SECRET_KEY = decouple.config(
'SECRET_KEY',
default='yc!+ii!psza0mi)&vnn_rdsip5ipdyr(0w8hjllxw6p)!wgo1e'
)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    BugPrecisa de AjudaIssues que precisam da ajuda da comunidade para serem resolvidas

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions