#32327: get_random_secret_key() should return a valid secret key
-------------------------------------+-------------------------------------
Reporter: Sumanth Ratna | Owner: nobody
Type: | Status: closed
Cleanup/optimization |
Component: Core (Management | Version: 3.1
commands) |
Severity: Normal | Resolution: wontfix
Keywords: | Triage Stage:
| Unreviewed
Has patch: 0 | Needs documentation: 0
Needs tests: 0 | Patch needs improvement: 0
Easy pickings: 1 | UI/UX: 0
-------------------------------------+-------------------------------------
Changes (by Mariusz Felisiak):
* status: new => closed
* type: Uncategorized => Cleanup/optimization
* resolution: => wontfix
Old description:
> [`check_secret_key()`](https://github.com/django/django/blob/6a054f768136de2caeaecf6c0fe9ffad76281373/django/core/checks/security/base.py#L192-L204)
> may return a W009 warning if the output of
> [`get_random_secret_key()`](https://github.com/django/django/blob/6a054f768136de2caeaecf6c0fe9ffad76281373/django/core/management/utils.py#L77-L82)
> has less than 5 unique characters. The probability of this occurring is
> extremely low (2.37595567e-25 if my math is correct), but this seems like
> a safe check to have anyway.
>
> The patch would be simple: wrap `get_random_secret_key()` in a do-while
> (or a `while`, because Python) to ensure that the returned secret key is
> secure.
New description:
[https://github.com/django/django/blob/6a054f768136de2caeaecf6c0fe9ffad76281373/django/core/checks/security/base.py#L192-L204
check_secret_key()] may return a W009 warning if the output of
[https://github.com/django/django/blob/6a054f768136de2caeaecf6c0fe9ffad76281373/django/core/management/utils.py#L77-L82
get_random_secret_key()] has less than 5 unique characters. The
probability of this occurring is extremely low (2.37595567e-25 if my math
is correct), but this seems like a safe check to have anyway.
The patch would be simple: wrap `get_random_secret_key()` in a do-while
(or a `while`, because Python) to ensure that the returned secret key is
secure.
--
Comment:
I don't think it's worth complexity, if someone will hit such secret they
should buy a lottery ticket and regenerate a secret key.
--
Ticket URL: <https://code.djangoproject.com/ticket/32327#comment:2>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.
--
You received this message because you are subscribed to the Google Groups
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To view this discussion on the web visit
https://groups.google.com/d/msgid/django-updates/070.9bae6db931e160f03c5db4927283c847%40djangoproject.com.