adventurelog: DEBUG=False on the backend — the image defaults to Django debug pages on the public origin (R-482)
gates / gates (push) Successful in 1s

This commit is contained in:
2026-09-13 19:22:35 +02:00
parent 48d2003b7e
commit ed2c01855b
2 changed files with 17 additions and 0 deletions
+13
View File
@@ -1,3 +1,16 @@
## adventurelog: Django DEBUG off on the public origin (2026-09-13, R-482)
**Found by the first nightly rotation walk on demo-hp** (`felhom.eu` `audits/nightly-2026-09-13-adventurelog/`):
the backend image defaults `DEBUG` to True, and it served full Django debug pages — settings, paths,
tracebacks — on the internet-facing subdomain (a 500 with a traceback on an unauthenticated POST; a
CSRF page that said *"you have DEBUG = True in your Django settings file"*). Upstream's own compose
sets `DEBUG=False`; this template did not. Now it does: one env line on the backend service, no
version moved. Proven on demo-hp after the sync: the same CSRF failure renders the short production
page (see `audits/v0240-2026-09-13/` in felhom.eu).
**Not measured, recorded:** `wger`, `tandoor` and `paperless-ngx` are Django too. Their images
default DEBUG off as far as their documentation says; each gets measured on its own rotation night.
## Live-test commits for controller slice 4, all reverted the same day (2026-09-13) — NO NET CHANGE
**`templates/glance` and `templates/uptime-kuma` are byte-identical to `3525e35`** (checked with
@@ -19,6 +19,10 @@ services:
environment:
- DJANGO_SECRET_KEY=${SECRET_KEY}
- SECRET_KEY=${SECRET_KEY}
# R-482: the image defaults DEBUG to True (settings: getenv('DEBUG','True')), which serves full
# Django debug pages — settings, paths, tracebacks — on the internet-facing origin. Measured
# 2026-09-13 on demo-hp. Upstream's own compose sets it False; so do we.
- DEBUG=False
- PGHOST=adventurelog-postgres
- PGDATABASE=adventurelog
- PGUSER=adventurelog