#32327: get_random_secret_key() should return a valid secret key
-------------------------------------+-------------------------------------
Reporter: Sumanth | Owner: nobody
Ratna |
Type: | Status: new
Uncategorized |
Component: Core | Version: 3.1
(Management commands) |
Severity: Normal | Keywords:
Triage Stage: | Has patch: 0
Unreviewed |
Needs documentation: 0 | Needs tests: 0
Patch needs improvement: 0 | Easy pickings: 1
UI/UX: 0 |
-------------------------------------+-------------------------------------
[`check_secret_key()`](https://github.com/django/django/blob/6a054f768136de2caeaecf6c0fe9ffad76281373/django/core/checks/security/base.py#L192-L204)
may return a W009 warning if the output of
[`get_random_secret_key()`](https://github.com/django/django/blob/6a054f768136de2caeaecf6c0fe9ffad76281373/django/core/management/utils.py#L77-L82)
has less than 5 unique characters. The probability of this occurring is
extremely low (2.37595567e-25 if my math is correct), but this seems like
a safe check to have anyway.
The patch would be simple: wrap `get_random_secret_key()` in a do-while
(or a `while`, because Python) to ensure that the returned secret key is
secure.
--
Ticket URL: <https://code.djangoproject.com/ticket/32327>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.
--
You received this message because you are subscribed to the Google Groups
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To view this discussion on the web visit
https://groups.google.com/d/msgid/django-updates/055.d2e231229fd0e682449b77f8c778f26c%40djangoproject.com.