From ed2c01855b111df8cb07a7b89ac3f7e02be557ac Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Sun, 13 Sep 2026 19:22:35 +0200 Subject: [PATCH] =?UTF-8?q?adventurelog:=20DEBUG=3DFalse=20on=20the=20back?= =?UTF-8?q?end=20=E2=80=94=20the=20image=20defaults=20to=20Django=20debug?= =?UTF-8?q?=20pages=20on=20the=20public=20origin=20(R-482)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- CHANGELOG.md | 13 +++++++++++++ templates/adventurelog/docker-compose.yml | 4 ++++ 2 files changed, 17 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 478b611..e732a16 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,16 @@ +## adventurelog: Django DEBUG off on the public origin (2026-09-13, R-482) + +**Found by the first nightly rotation walk on demo-hp** (`felhom.eu` `audits/nightly-2026-09-13-adventurelog/`): +the backend image defaults `DEBUG` to True, and it served full Django debug pages — settings, paths, +tracebacks — on the internet-facing subdomain (a 500 with a traceback on an unauthenticated POST; a +CSRF page that said *"you have DEBUG = True in your Django settings file"*). Upstream's own compose +sets `DEBUG=False`; this template did not. Now it does: one env line on the backend service, no +version moved. Proven on demo-hp after the sync: the same CSRF failure renders the short production +page (see `audits/v0240-2026-09-13/` in felhom.eu). + +**Not measured, recorded:** `wger`, `tandoor` and `paperless-ngx` are Django too. Their images +default DEBUG off as far as their documentation says; each gets measured on its own rotation night. + ## Live-test commits for controller slice 4, all reverted the same day (2026-09-13) — NO NET CHANGE **`templates/glance` and `templates/uptime-kuma` are byte-identical to `3525e35`** (checked with diff --git a/templates/adventurelog/docker-compose.yml b/templates/adventurelog/docker-compose.yml index b3f20cb..09d0996 100644 --- a/templates/adventurelog/docker-compose.yml +++ b/templates/adventurelog/docker-compose.yml @@ -19,6 +19,10 @@ services: environment: - DJANGO_SECRET_KEY=${SECRET_KEY} - SECRET_KEY=${SECRET_KEY} + # R-482: the image defaults DEBUG to True (settings: getenv('DEBUG','True')), which serves full + # Django debug pages — settings, paths, tracebacks — on the internet-facing origin. Measured + # 2026-09-13 on demo-hp. Upstream's own compose sets it False; so do we. + - DEBUG=False - PGHOST=adventurelog-postgres - PGDATABASE=adventurelog - PGUSER=adventurelog