adventurelog: DEBUG=False on the backend — the image defaults to Django debug pages on the public origin (R-482)
gates / gates (push) Successful in 1s
gates / gates (push) Successful in 1s
This commit is contained in:
@@ -1,3 +1,16 @@
|
||||
## adventurelog: Django DEBUG off on the public origin (2026-09-13, R-482)
|
||||
|
||||
**Found by the first nightly rotation walk on demo-hp** (`felhom.eu` `audits/nightly-2026-09-13-adventurelog/`):
|
||||
the backend image defaults `DEBUG` to True, and it served full Django debug pages — settings, paths,
|
||||
tracebacks — on the internet-facing subdomain (a 500 with a traceback on an unauthenticated POST; a
|
||||
CSRF page that said *"you have DEBUG = True in your Django settings file"*). Upstream's own compose
|
||||
sets `DEBUG=False`; this template did not. Now it does: one env line on the backend service, no
|
||||
version moved. Proven on demo-hp after the sync: the same CSRF failure renders the short production
|
||||
page (see `audits/v0240-2026-09-13/` in felhom.eu).
|
||||
|
||||
**Not measured, recorded:** `wger`, `tandoor` and `paperless-ngx` are Django too. Their images
|
||||
default DEBUG off as far as their documentation says; each gets measured on its own rotation night.
|
||||
|
||||
## Live-test commits for controller slice 4, all reverted the same day (2026-09-13) — NO NET CHANGE
|
||||
|
||||
**`templates/glance` and `templates/uptime-kuma` are byte-identical to `3525e35`** (checked with
|
||||
|
||||
@@ -19,6 +19,10 @@ services:
|
||||
environment:
|
||||
- DJANGO_SECRET_KEY=${SECRET_KEY}
|
||||
- SECRET_KEY=${SECRET_KEY}
|
||||
# R-482: the image defaults DEBUG to True (settings: getenv('DEBUG','True')), which serves full
|
||||
# Django debug pages — settings, paths, tracebacks — on the internet-facing origin. Measured
|
||||
# 2026-09-13 on demo-hp. Upstream's own compose sets it False; so do we.
|
||||
- DEBUG=False
|
||||
- PGHOST=adventurelog-postgres
|
||||
- PGDATABASE=adventurelog
|
||||
- PGUSER=adventurelog
|
||||
|
||||
Reference in New Issue
Block a user