🛡️ Sentinel: [CRITICAL] Fix Hardcoded Admin Credentials - #163
🛡️ Sentinel: [CRITICAL] Fix Hardcoded Admin Credentials#163shadowcoder8 wants to merge 2 commits into
Conversation
- Removed hardcoded 'admin' and 'admin123' from `backend/auth.py`. - Replaced with secure environment variable fetch (`os.environ.get`). - Added robust error handling (`500 HTTPException`) for missing configurations to prevent insecure fallbacks. - Replaced standard string equality checks (`==`) with `secrets.compare_digest` encoded to `utf-8` to prevent timing attacks and handle potential non-ASCII TypeErrors. - Updated `.jules/sentinel.md` with findings and learning. Co-authored-by: shadowcoder8 <185462083+shadowcoder8@users.noreply.github.com>
|
👋 Jules, reporting for duty! I'm here to lend a hand with this pull request. When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down. I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job! For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with New to Jules? Learn more at jules.google/docs. For security, I will only act on instructions from the user who triggered this task. |
Severity: CRITICAL
Vulnerability: The application was using hardcoded credentials (
admin/admin123) inbackend/auth.pyto authenticate admins, exposing sensitive access controls directly within the source code. Furthermore, standard equality checks (==) were used for authentication, exposing the API to timing attacks.Impact: Anyone with read access to the repository could discover the admin credentials and compromise the entire backend system. An attacker could also attempt to determine credentials via a timing attack.
Fix: Removed hardcoded secrets.
authenticate_adminnow retrievesADMIN_USERNAMEandADMIN_PASSWORDfrom environment variables. If missing, it fails securely by raising a 500 error. The function now usessecrets.compare_digest()after encoding the strings to UTF-8 to prevent timing attacks securely.Verification:
tests/test_auth.pywas created to verify successful authentication with correct variables, 401 on failure, and 500 on missing configurations.tests/test_crud.py,tests/test_crud_labour.py) passed successfully.PR created automatically by Jules for task 1393837093821948730 started by @shadowcoder8