Security Audit: Credentials aus Code entfernen, Haertung #119
Labels
No Milestone
No project
No Assignees
1 Participants
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: tobias/gwoe-antragspruefer#119
Loading…
Reference in New Issue
Block a user
No description provided.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Kritisch
main.py(Zeilen 470, 505, 533) — muss in ENV-VariableHoch
Mittel
Niedrig
Kritisch erledigt: Keycloak-Admin-PW aus main.py entfernt, via ENV-Variable + keycloak_admin_token() Helper in auth.py. Hardcoded sso.toppyr.de URLs durch settings.keycloak_url ersetzt. Verbleibend: Cookie-Flags, CSP-Header, Rate-Limiting auf Auth, pip-audit.
Erledigt
Noch offen