mirror of
https://github.com/suitenumerique/meet.git
synced 2026-10-07 22:10:56 +00:00
🔒️(backend) prevent editing client id and secret in Django admin
The client id and client secret are auto-generated with high entropy when an application is created. Allowing them to be edited from the Django admin let any administrator replace them with a short or weak value, undermining that guarantee. Make both fields read-only in the admin so they can only be regenerated through the intended flow.
This commit is contained in:
committed by
aleb_the_flash
parent
0450c74f53
commit
080c347129
@@ -12,6 +12,10 @@ and this project adheres to
|
||||
|
||||
- ⚡️(backend) hash application secrets with SHA-256
|
||||
|
||||
### Fixed
|
||||
|
||||
- 🔒️(backend) prevent editing client id and secret in Django admin
|
||||
|
||||
## [1.34.0] - 2026-10-07
|
||||
|
||||
### Added
|
||||
|
||||
@@ -483,6 +483,11 @@ class ApplicationAdminForm(forms.ModelForm):
|
||||
if self.instance.pk and self.instance.scopes:
|
||||
self.fields["scopes"].initial = self.instance.scopes
|
||||
|
||||
# On creation: display generated credentials without allowing edits
|
||||
for name in ("client_id", "client_secret"):
|
||||
if name in self.fields:
|
||||
self.fields[name].widget.attrs["readonly"] = True
|
||||
|
||||
|
||||
@admin.register(models.Application)
|
||||
class ApplicationAdmin(admin.ModelAdmin):
|
||||
|
||||
Reference in New Issue
Block a user