Re: [Cloud] PSA about secrets

2020-01-29 Thread Nick Wilson (Quiddity)
Roy, I will quote from https://www.mediawiki.org/wiki/Reporting_security_bugs "We support responsible disclosure and we hope that anyone who finds a potential security issue in our ecosystem acts with discretion and forbearance" Thank you. For

[Cloud] PSA about secrets

2020-01-29 Thread Roy Smith
I was poking around in /data/project/ just now, looking for examples of how other tools set up their django apps. I was surprised (well, only a little) to discover that there's a few world-readable app.py files that have their django_secrets embedded in them. That's not a good idea folks. Sec