Commit bb02217
authored
* fix: gate Flask debug / Werkzeug debugger behind opt-in flag (closes #9)
The Werkzeug debugger is a documented remote-code-execution primitive.
app.py was hard-coding `debug=True`, which exposed RCE to anyone who
could reach the listening port — a misconfigured `--host`, an SSH
tunnel, or a careless reverse proxy was enough.
- Remove the `debug=True` literal from app.py.
- Default debug OFF. Opt-in via either `--debug` CLI flag or
`FLASK_DEBUG=1` env var (truthy = "1" / "true" / "yes",
case-insensitive, whitespace-tolerant).
- Print a stderr WARNING when debug is enabled, naming the RCE risk
and reminding the operator to bind only to loopback.
- Gate the auto-reloader on the same flag.
Live-tested all four matrix cells: (default off / --debug / FLASK_DEBUG=1
/ FLASK_DEBUG=0). Bogus paths under debug-off return a plain Flask 404,
not the Werkzeug debugger console.
Helper `resolve_debug_flag(env_value, cli_flag)` lives in
`utils/debug_flag.py` so it can be unit-tested without importing Flask
(matching the existing test convention in tests/test_cli_args.py).
Regression coverage in tests/test_cli_args.py adds 8 cases:
- default-off, env-truthy, env-falsey, CLI override
- argparse `--debug` default + explicit
- source-level guard that fails if `debug=True` is reintroduced
* test: AST-walk the debug=True regression guard (CodeRabbit on PR #10)
Old guard: `self.assertNotIn("debug=True", src)` — substring match.
That misses cosmetic variants like `debug = True` (with spaces),
multi-line `debug=\n True`, or any other form that produces the
same runtime semantics. CodeRabbit correctly flagged it as evadable.
Replaced with an `ast.walk(tree)` over the parsed app.py: find any
`ast.Call` whose keywords contain `debug=True` as a literal Constant.
Catches every cosmetic variant by definition.
Failure message includes the offending line number(s) and the
rationale (issue #9), so a future CI break is immediately
debuggable.
Verified by injecting `debug = True` (with spaces — the form the
old check missed) into app.py:
- Old check: would have passed (false negative).
- New check: failed with `[136]` and the issue-#9 message.
Then reverted the inject; test passes again.
42/42 tests still pass on the actual app.py.
* review: address PR #20 nits — broaden debug=True guard + FLASK_DEBUG note
- AST guard now handles ast.NameConstant (Py3.7) and **{"debug":True}
dict-spread bypass; helper extracted for unit testing.
- README: opt-in note for the Werkzeug debugger, including that
FLASK_ENV=development is NOT consulted (only FLASK_DEBUG=1).
- Replace em dashes in app.py comments with ASCII to silence GitHub's
non-ASCII banner on review.
1 parent cad215f commit bb02217
4 files changed
Lines changed: 201 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
69 | 69 | | |
70 | 70 | | |
71 | 71 | | |
| 72 | + | |
| 73 | + | |
72 | 74 | | |
73 | 75 | | |
74 | 76 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | | - | |
| 2 | + | |
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| 7 | + | |
7 | 8 | | |
8 | 9 | | |
9 | 10 | | |
10 | 11 | | |
11 | 12 | | |
12 | 13 | | |
| 14 | + | |
| 15 | + | |
13 | 16 | | |
14 | 17 | | |
15 | 18 | | |
| |||
101 | 104 | | |
102 | 105 | | |
103 | 106 | | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
104 | 114 | | |
105 | 115 | | |
106 | 116 | | |
| |||
109 | 119 | | |
110 | 120 | | |
111 | 121 | | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
112 | 135 | | |
113 | 136 | | |
114 | 137 | | |
115 | 138 | | |
116 | | - | |
117 | | - | |
| 139 | + | |
| 140 | + | |
118 | 141 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
9 | 9 | | |
10 | 10 | | |
11 | 11 | | |
| 12 | + | |
12 | 13 | | |
13 | 14 | | |
14 | 15 | | |
| |||
43 | 44 | | |
44 | 45 | | |
45 | 46 | | |
| 47 | + | |
46 | 48 | | |
47 | 49 | | |
48 | 50 | | |
| |||
246 | 248 | | |
247 | 249 | | |
248 | 250 | | |
| 251 | + | |
| 252 | + | |
| 253 | + | |
| 254 | + | |
| 255 | + | |
| 256 | + | |
| 257 | + | |
| 258 | + | |
| 259 | + | |
| 260 | + | |
| 261 | + | |
| 262 | + | |
| 263 | + | |
| 264 | + | |
| 265 | + | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
| 272 | + | |
| 273 | + | |
| 274 | + | |
| 275 | + | |
| 276 | + | |
| 277 | + | |
| 278 | + | |
| 279 | + | |
| 280 | + | |
| 281 | + | |
| 282 | + | |
| 283 | + | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
| 287 | + | |
| 288 | + | |
| 289 | + | |
| 290 | + | |
| 291 | + | |
| 292 | + | |
| 293 | + | |
| 294 | + | |
| 295 | + | |
| 296 | + | |
| 297 | + | |
| 298 | + | |
| 299 | + | |
| 300 | + | |
| 301 | + | |
| 302 | + | |
| 303 | + | |
| 304 | + | |
| 305 | + | |
| 306 | + | |
| 307 | + | |
| 308 | + | |
| 309 | + | |
| 310 | + | |
| 311 | + | |
| 312 | + | |
| 313 | + | |
| 314 | + | |
| 315 | + | |
| 316 | + | |
| 317 | + | |
| 318 | + | |
| 319 | + | |
| 320 | + | |
| 321 | + | |
| 322 | + | |
| 323 | + | |
| 324 | + | |
| 325 | + | |
| 326 | + | |
| 327 | + | |
| 328 | + | |
| 329 | + | |
| 330 | + | |
| 331 | + | |
| 332 | + | |
| 333 | + | |
| 334 | + | |
| 335 | + | |
| 336 | + | |
| 337 | + | |
| 338 | + | |
| 339 | + | |
| 340 | + | |
| 341 | + | |
| 342 | + | |
| 343 | + | |
| 344 | + | |
| 345 | + | |
| 346 | + | |
| 347 | + | |
| 348 | + | |
| 349 | + | |
| 350 | + | |
| 351 | + | |
| 352 | + | |
| 353 | + | |
| 354 | + | |
| 355 | + | |
| 356 | + | |
| 357 | + | |
| 358 | + | |
| 359 | + | |
| 360 | + | |
| 361 | + | |
| 362 | + | |
| 363 | + | |
| 364 | + | |
| 365 | + | |
| 366 | + | |
| 367 | + | |
| 368 | + | |
| 369 | + | |
| 370 | + | |
| 371 | + | |
| 372 | + | |
| 373 | + | |
| 374 | + | |
| 375 | + | |
| 376 | + | |
| 377 | + | |
| 378 | + | |
| 379 | + | |
| 380 | + | |
| 381 | + | |
| 382 | + | |
| 383 | + | |
| 384 | + | |
| 385 | + | |
| 386 | + | |
| 387 | + | |
| 388 | + | |
| 389 | + | |
| 390 | + | |
| 391 | + | |
| 392 | + | |
| 393 | + | |
| 394 | + | |
| 395 | + | |
| 396 | + | |
| 397 | + | |
| 398 | + | |
| 399 | + | |
| 400 | + | |
249 | 401 | | |
250 | 402 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
0 commit comments