Config file app.ini is 644 #2859

Closed
opened 2025-11-02 04:51:42 -06:00 by GiteaMirror · 0 comments
Owner

Originally created by @marcvs on GitHub (Feb 4, 2019).

  • Gitea version (or commit ref): 1.7.1
  • Operating system: debian/buster
  • Database (use [x]):
    • PostgreSQL
    • MySQL
    • MSSQL
    • SQLite
  • Can you reproduce the bug at https://try.gitea.io:
    • Yes (provide example URL)
    • No
    • Not relevant
  • Log gist:

Description

I created a config from the standalone binary. Very nice!

Just: I've provided the smtp password for sending emails and I find this unencryped password in the app.ini config file.

Please chmod 600 this file!

Originally created by @marcvs on GitHub (Feb 4, 2019). - Gitea version (or commit ref): 1.7.1 - Operating system: debian/buster - Database (use `[x]`): - [ ] PostgreSQL - [ ] MySQL - [ ] MSSQL - [x] SQLite - Can you reproduce the bug at https://try.gitea.io: - [ ] Yes (provide example URL) - [ ] No - [x] Not relevant - Log gist: ## Description I created a config from the standalone binary. Very nice! Just: I've provided the smtp password for sending emails and I find this unencryped password in the app.ini config file. Please chmod 600 this file!
GiteaMirror added the type/proposaltopic/security labels 2025-11-02 04:51:42 -06:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/gitea#2859