Do not default pecan_debug to CONF.debug
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
openstack-manuals |
Fix Released
|
Low
|
Ildiko Vancsa |
Bug Description
https:/
commit b2a21fba08df7da
Author: Jim Rollenhagen <email address hidden>
Date: Tue Feb 24 21:56:53 2015 +0000
Do not default pecan_debug to CONF.debug
Pecan's debug mode can be terribly insecure; 500 errors return a
Python traceback, the full list of environment variables, and a
button to replay the request with a breakpoint.
Deployers often run OpenStack services in debug mode; doing so should
not open the service up to these flaws. Defaulting pecan_debug to
CONF.debug makes this easy to accidentally do. So, default it to False
rather than riding on top of CONF.debug.
Change-Id: I70f9c9807d16aa
Closes-Bug: #1425206
DocImpact
Changed in openstack-manuals: | |
assignee: | nobody → Ildiko Vancsa (ildiko-vancsa) |
This will be picked up by the next run of autogenerate- config- docs - no need to manually fix.