From 080c347129884cfaa2407d2cc6924569031f9a06 Mon Sep 17 00:00:00 2001 From: lebaudantoine Date: Wed, 23 Sep 2026 17:55:14 +0200 Subject: [PATCH] =?UTF-8?q?=F0=9F=94=92=EF=B8=8F(backend)=20prevent=20edit?= =?UTF-8?q?ing=20client=20id=20and=20secret=20in=20Django=20admin?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The client id and client secret are auto-generated with high entropy when an application is created. Allowing them to be edited from the Django admin let any administrator replace them with a short or weak value, undermining that guarantee. Make both fields read-only in the admin so they can only be regenerated through the intended flow. --- CHANGELOG.md | 4 ++++ src/backend/core/admin.py | 5 +++++ 2 files changed, 9 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 88ac5a5cf..432303eda 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -12,6 +12,10 @@ and this project adheres to - ⚡️(backend) hash application secrets with SHA-256 +### Fixed + +- 🔒️(backend) prevent editing client id and secret in Django admin + ## [1.34.0] - 2026-10-07 ### Added diff --git a/src/backend/core/admin.py b/src/backend/core/admin.py index b5eb0d4ca..30138e85e 100644 --- a/src/backend/core/admin.py +++ b/src/backend/core/admin.py @@ -483,6 +483,11 @@ class ApplicationAdminForm(forms.ModelForm): if self.instance.pk and self.instance.scopes: self.fields["scopes"].initial = self.instance.scopes + # On creation: display generated credentials without allowing edits + for name in ("client_id", "client_secret"): + if name in self.fields: + self.fields[name].widget.attrs["readonly"] = True + @admin.register(models.Application) class ApplicationAdmin(admin.ModelAdmin):