FileCodeBox icon indicating copy to clipboard operation
FileCodeBox copied to clipboard

Potential Information Leakage

Open nevercodecorrect opened this issue 1 year ago • 1 comments

Describe the bug In the settings' __init__ function, it stores sensitive data including onedrive password, AWS key into a plaintext env file which is a potential security issue described in CWE-312.

To Reproduce Steps to reproduce the behavior: Run the settings function.

Expected behavior The password should stay in the memory or change the env file permission to only available to the user running the service.

nevercodecorrect avatar Feb 18 '24 20:02 nevercodecorrect

thank you,I will update it

vastsa avatar Feb 19 '24 12:02 vastsa

File storage deleted

vastsa avatar Jun 15 '24 12:06 vastsa