🔒️(backend) prevent editing client id and secret in Django admin

The client id and client secret are auto-generated with high entropy
when an application is created. Allowing them to be edited from the
Django admin let any administrator replace them with a short or
weak value, undermining that guarantee.

Make both fields read-only in the admin so they can only be
regenerated through the intended flow.
This commit is contained in:
lebaudantoine
2026-09-23 17:55:14 +02:00
committed by aleb_the_flash
parent 0450c74f53
commit 080c347129
2 changed files with 9 additions and 0 deletions
+4
View File
@@ -12,6 +12,10 @@ and this project adheres to
- ⚡️(backend) hash application secrets with SHA-256
### Fixed
- 🔒️(backend) prevent editing client id and secret in Django admin
## [1.34.0] - 2026-10-07
### Added
+5
View File
@@ -483,6 +483,11 @@ class ApplicationAdminForm(forms.ModelForm):
if self.instance.pk and self.instance.scopes:
self.fields["scopes"].initial = self.instance.scopes
# On creation: display generated credentials without allowing edits
for name in ("client_id", "client_secret"):
if name in self.fields:
self.fields[name].widget.attrs["readonly"] = True
@admin.register(models.Application)
class ApplicationAdmin(admin.ModelAdmin):