fix: stop the application database role reusing the admin password
docker-compose.yml passed POSTGRES_PASSWORD as APP_DB_PASSWORD, so the DML-only dtf_app role and the owning administrator shared one credential and the privilege separation bootstrap.py sets up was decorative. APP_DB_PASSWORD is now its own required variable, and bootstrap refuses to run when it matches the administrator password, in both the URL and discrete-field configuration forms. Deploying this requires APP_DB_PASSWORD to be set in the stack environment first; db-init rotates the role to it on the same deploy. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -5,7 +5,9 @@ x-app-environment: &app-environment
|
||||
DATABASE_HOST: db
|
||||
DATABASE_NAME: dtf
|
||||
DATABASE_USER: dtf_app
|
||||
DATABASE_PASSWORD: ${POSTGRES_PASSWORD:?set POSTGRES_PASSWORD}
|
||||
# Must differ from POSTGRES_PASSWORD: the runtime role is DML-only, and reusing
|
||||
# the administrator credential would make that restriction meaningless.
|
||||
DATABASE_PASSWORD: ${APP_DB_PASSWORD:?set APP_DB_PASSWORD}
|
||||
S3_ENDPOINT: ${R2_ENDPOINT:?set R2_ENDPOINT}
|
||||
S3_PUBLIC_ENDPOINT: ${R2_ENDPOINT:?set R2_ENDPOINT}
|
||||
S3_BUCKET: ${R2_BUCKET:?set R2_BUCKET}
|
||||
@@ -62,7 +64,7 @@ services:
|
||||
DATABASE_ADMIN_USER: dtf_admin
|
||||
DATABASE_ADMIN_PASSWORD: ${POSTGRES_PASSWORD:?set POSTGRES_PASSWORD}
|
||||
APP_DB_USER: dtf_app
|
||||
APP_DB_PASSWORD: ${POSTGRES_PASSWORD:?set POSTGRES_PASSWORD}
|
||||
APP_DB_PASSWORD: ${APP_DB_PASSWORD:?set APP_DB_PASSWORD}
|
||||
networks: [backend]
|
||||
deploy:
|
||||
replicas: 1
|
||||
|
||||
Reference in New Issue
Block a user