security: R-925 — live secrets committed to a world-readable Gitea repo
gates / gates (push) Successful in 5m45s

Found while publishing the legal pages: a background security review flagged
the <!-- source --> comments served in website/adatkezeles.html. Chasing what
those comments point AT found something larger.

MEASURED, and the control is what makes it mean anything:
  - manifest_bearer_gate.py itself prints
    "manifests/felhom.secret.yaml:39 KNOWN-BACKLOG committed secret"
  - that file holds live-shaped values, not placeholders: SECRET_KEY (69),
    SUPERUSER_PASSWORD (18), Umami APP_SECRET (66) and POSTGRES_PASSWORD (34),
    plus a username/password pair. Values were never printed, only measured
    by length.
  - gitea.dooplex.hu resolves to 37.191.56.193, the website's public address
  - anonymous curl: 200 and 1686 bytes for that file; 200 for hub internals
  - OFF-NETWORK CONTROL: fetched from outside the operator's network, a real
    path returns the file's first line and a nonsense path returns 404. So
    the 200 is genuine anonymous read from the internet, not a LAN-only ACL.

This contradicts documentation/runbooks/secrets.md:3-4, which states secret
values are never committed and the manifests carry only placeholders. That
promise is false today.

Ranked P2, not P1, and the row says why so the operator can overrule: the
exposed credentials guard analytics and an undeployed healthchecks instance,
NOT household data. Measured: umami-db is a ClusterIP service with no
external IP, so the Postgres password is not internet-reachable. No customer
box, hub token or escrow key is in the file.

NOTHING WAS CHANGED. Making the repo private could break the public day-0
installer path (R-110), and rotation plus repo visibility are operator
decisions on production infrastructure. The row carries the order: rotate
first (de-git alone kills nothing — the runbook says so), then decide
visibility, then CC does the de-git and tightens the gate.

Coupled and easy to miss: the 32 source comments on /adatkezeles are harmless
while the repo is public, but become a map of it the moment it is private, so
that is one change and not two. Their traceability is already kept in
documentation/legal/*-1.0.md.
This commit is contained in:
2026-10-09 12:20:52 +02:00
parent 4c388a398b
commit 2c48feb325
2 changed files with 23 additions and 1 deletions
+21
View File
@@ -35,6 +35,27 @@
- **Still to prove:** the lost off-site copy alarm (Tester 1's next clean-up
window, about 12 October), and the failed-restore hold (needs a scratch off-site store).
## Needs you soon (2026-10-09): passwords are sitting in a repository anyone on the internet can read
I found this while publishing the legal pages, not because I went looking — a security check flagged something
small in the new page, and following it led here.
- **What is true:** `gitea.dooplex.hu` answers to anyone, with no login, from anywhere on the internet. I proved
that from outside your network, not just from DooPlex. One of the files it hands out is a manifest that
contains **real passwords**, not placeholders: the visitor-counter's database password and app key, and the
login for the health-check tool. I did not print or copy any of the values.
- **How bad:** not as bad as it sounds, and I want to be exact. These guard the **statistics and monitoring
bits, not any household's data.** The database itself is not reachable from the internet — I checked. No
customer box, no hub key, no backup key is in that file. But they are live passwords, publicly downloadable.
- **Your own runbook already says this must not happen** — "secret values are never committed to git" — so the
rule is right and the repository is breaking it.
- **What to do, in this order:** (1) **change those passwords** — deleting them from the files changes nothing,
the history keeps them; (2) decide whether that repository should be readable by strangers at all, bearing in
mind the installer people download depends on something public; (3) then I move the values out properly and
make the check refuse them in future.
- **I changed nothing.** Making the repository private could break the installer that new boxes fetch, and
changing passwords on live services is yours to time. It is written up as a register item with the evidence.
## Legal pages (2026-10-09): the website finally says what it does with people's data
- **Two new pages are live:** <https://felhom.eu/adatkezeles> (what we do with data) and