Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Fixes #7535] Issues with .env GEOSERVER_ADMIN_PASSWORD #9911

Open
wants to merge 2 commits into
base: master
Choose a base branch
from

Conversation

jthurner
Copy link

When initializing the geonode stack with docker, the password for the geoserver admin user is changed from the default to the value of $GEOSERVER_ADMIN_PASSWORD. Subsequent password changes require manual intervention to update the password in geoserver (even if FORCE_REINIT=true).

OGC_SERVER_DEFAULT_PASSWORD and OGC_SERVER_DEFAULT_USER are redundant as they always took the value of GEOSERVER_ADMIN_PASSWORD/GEOSERVER_ADMIN_USER if defined, replaced with GEOSERVER_ADMIN_PASSWORD/GEOSERVER_ADMIN_USER to avoid confusion.

Corresponding issues in geonode-project:

Checklist

For all pull requests:

  • Confirm you have read the contribution guidelines
  • You have sent a Contribution Licence Agreement (CLA) as necessary (not required for small changes, e.g., fixing typos in the documentation)
  • Make sure the first PR targets the master branch, eventual backports will be managed later. This can be ignored if the PR is fixing an issue that only happens in a specific branch, but not in newer ones.

The following are required only for core and extension modules (they are welcomed, but not required, for contrib modules):

  • There is a ticket in https://github.com/GeoNode/geonode/issues describing the issue/improvement/feature (a notable exemption is, changes not visible to end-users)
  • The issue connected to the PR must have Labels and Milestone assigned
  • PR for bug fixes and small new features are presented as a single commit
  • Commit message must be in the form "[Fixes #<issue_number>] Title of the Issue"
  • New unit tests have been added covering the changes, unless there is an explanation on why the tests are not necessary/implemented
  • This PR passes all existing unit tests (test results will be reported by travis-ci after opening this PR)
  • This PR passes the QA checks: flake8 geonode
  • Commits changing the settings, UI, existing user workflows, or adding new functionality, need to include documentation updates
  • Commits adding new texts do use gettext and have updated .po / .mo files (without location infos)

Submitting the PR does not require you to check all items, but by the time it gets merged, they should be either satisfied or inapplicable.

* geoserver admin password is only changed from the default during init
* geoserver has to be manually updated for subsequent password changes
* drop redundant OGC_SERVER_DEFAULT_PASSWORD/OGC_SERVER_DEFAULT_USER variables
@cla-bot
Copy link

cla-bot bot commented Aug 26, 2022

Thank you for your pull request and welcome to our community. We require contributors to sign our Contributor License Agreement, and we don't seem to have the users @jthurner on file. In order for us to review and merge your code, please contact the project maintainers to get yourself added.

@cla-bot
Copy link

cla-bot bot commented Aug 26, 2022

Thank you for your pull request and welcome to our community. We require contributors to sign our Contributor License Agreement, and we don't seem to have the users @jthurner on file. In order for us to review and merge your code, please contact the project maintainers to get yourself added.

@codecov
Copy link

codecov bot commented Aug 26, 2022

Codecov Report

Merging #9911 (dc5a082) into master (a85faae) will decrease coverage by 0.00%.
The diff coverage is 50.00%.

@@            Coverage Diff             @@
##           master    #9911      +/-   ##
==========================================
- Coverage   61.39%   61.38%   -0.01%     
==========================================
  Files         823      823              
  Lines       50328    50328              
  Branches     7746     7746              
==========================================
- Hits        30898    30896       -2     
- Misses      17753    17756       +3     
+ Partials     1677     1676       -1     

@gitguardian
Copy link

gitguardian bot commented Nov 23, 2022

⚠️ GitGuardian has uncovered 1 secret following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

🔎 Detected hardcoded secret in your pull request
GitGuardian id Secret Commit Filename
- Django Secret Key 63f1c8d .env.sample View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secret safely. Learn here the best practices.
  3. Revoke and rotate this secret.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

Our GitHub checks need improvements? Share your feedbacks!

@t-book
Copy link
Contributor

t-book commented Feb 8, 2023

@jthurner your CLA is missing: https://github.com/GeoNode/geonode/blob/master/CONTRIBUTING.md
@giohappy @mattiagiupponi old PR (28/08/22) but useful? Should I test it?

@ridoo
Copy link
Contributor

ridoo commented Nov 2, 2023

This PR may have become superseded. It seems that the fixture to change the geoserver password got removed completely. This is actually good, as this raised so many issues.

@afabiani as you did the change, you should decide on this issue. What about all the other open issues targeting the same problem? I did a quick naive search and have the impression that a lot of them originate to the same problem.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants