The image never sets NODE_ENV, so Express reports app.get('env') as development. wiki-server then takes its development branch (wiki-server/lib/server.js, around lines 343–349 in wiki-server 0.28.0-rc.0):
if('development'==app.get('env')){app.use(errorHandler())argv.debug=true}// Show all of the options a server is using.
log(argv)
Two effects in a farm:
Each site's startup prints its whole option set to the container log, including cookieSecret and every wikiDomains entry's oauth2_clientSecret. Anyone who can read the service logs can read the secrets.
errorhandler is mounted, which answers visitors with stack traces on errors.
Seen with 0.41.0-rc.2-2; the branch predates it.
Proposed fix: ENV NODE_ENV=production in the Containerfile, so every deployment of the image gets it without a recipe change. A deployment can still opt back into development mode with NODE_ENV=development.
Separately, printing secrets even in debug mode is an upstream wiki-server matter worth reporting there; this issue covers the image default.
The image never sets `NODE_ENV`, so Express reports `app.get('env')` as `development`. wiki-server then takes its development branch (`wiki-server/lib/server.js`, around lines 343–349 in wiki-server 0.28.0-rc.0):
```js
if ('development' == app.get('env')) {
app.use(errorHandler())
argv.debug = true
}
// Show all of the options a server is using.
log(argv)
```
Two effects in a farm:
- Each site's startup prints its whole option set to the container log, including `cookieSecret` and every `wikiDomains` entry's `oauth2_clientSecret`. Anyone who can read the service logs can read the secrets.
- `errorhandler` is mounted, which answers visitors with stack traces on errors.
Seen with 0.41.0-rc.2-2; the branch predates it.
Proposed fix: `ENV NODE_ENV=production` in the Containerfile, so every deployment of the image gets it without a recipe change. A deployment can still opt back into development mode with `NODE_ENV=development`.
Separately, printing secrets even in debug mode is an upstream wiki-server matter worth reporting there; this issue covers the image default.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The image never sets
NODE_ENV, so Express reportsapp.get('env')asdevelopment. wiki-server then takes its development branch (wiki-server/lib/server.js, around lines 343–349 in wiki-server 0.28.0-rc.0):Two effects in a farm:
cookieSecretand everywikiDomainsentry'soauth2_clientSecret. Anyone who can read the service logs can read the secrets.errorhandleris mounted, which answers visitors with stack traces on errors.Seen with 0.41.0-rc.2-2; the branch predates it.
Proposed fix:
ENV NODE_ENV=productionin the Containerfile, so every deployment of the image gets it without a recipe change. A deployment can still opt back into development mode withNODE_ENV=development.Separately, printing secrets even in debug mode is an upstream wiki-server matter worth reporting there; this issue covers the image default.