docker-compose.yml passed POSTGRES_PASSWORD as APP_DB_PASSWORD, so the DML-only dtf_app role and the owning administrator shared one credential and the privilege separation bootstrap.py sets up was decorative. APP_DB_PASSWORD is now its own required variable, and bootstrap refuses to run when it matches the administrator password, in both the URL and discrete-field configuration forms. Deploying this requires APP_DB_PASSWORD to be set in the stack environment first; db-init rotates the role to it on the same deploy. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
5.8 KiB
5.8 KiB