Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Stacktrace inspector allows users to see any file on the filesystem #10

Closed
ionelmc opened this issue Jun 7, 2014 · 2 comments
Closed

Comments

@ionelmc
Copy link

ionelmc commented Jun 7, 2014

Including everything in settings.py ...

@mtford90
Copy link
Collaborator

mtford90 commented Jun 7, 2014

Yeah was made aware of this earlier - one of many things that needs to be fixed/added if this were to ever be used in a prod environment!

Cheers!

mtford90 added a commit that referenced this issue Jun 10, 2014
@mtford90
Copy link
Collaborator

This is now fixed in Master. 403 if attempting to access a file not in the stack trace.

yaroslav0114 pushed a commit to yaroslav0114/django-silk that referenced this issue Dec 17, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants