The patch would be simple: wrap `get_random_secret_key()` in a do-while
(or a `while`, because Python) to ensure that the returned secret key is
secure.
--
Ticket URL: <https://code.djangoproject.com/ticket/32327>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.
Comment (by Sumanth Ratna):
(by the way, feel free to close since the probability that the described
issue occurs is practically 0)
--
Ticket URL: <https://code.djangoproject.com/ticket/32327#comment:1>
* status: new => closed
* type: Uncategorized => Cleanup/optimization
* resolution: => wontfix
Old description:
> [`check_secret_key()`](https://github.com/django/django/blob/6a054f768136de2caeaecf6c0fe9ffad76281373/django/core/checks/security/base.py#L192-L204)
> may return a W009 warning if the output of
> [`get_random_secret_key()`](https://github.com/django/django/blob/6a054f768136de2caeaecf6c0fe9ffad76281373/django/core/management/utils.py#L77-L82)
> has less than 5 unique characters. The probability of this occurring is
> extremely low (2.37595567e-25 if my math is correct), but this seems like
> a safe check to have anyway.
>
> The patch would be simple: wrap `get_random_secret_key()` in a do-while
> (or a `while`, because Python) to ensure that the returned secret key is
> secure.
New description:
[https://github.com/django/django/blob/6a054f768136de2caeaecf6c0fe9ffad76281373/django/core/checks/security/base.py#L192-L204
check_secret_key()] may return a W009 warning if the output of
[https://github.com/django/django/blob/6a054f768136de2caeaecf6c0fe9ffad76281373/django/core/management/utils.py#L77-L82
get_random_secret_key()] has less than 5 unique characters. The
probability of this occurring is extremely low (2.37595567e-25 if my math
is correct), but this seems like a safe check to have anyway.
The patch would be simple: wrap `get_random_secret_key()` in a do-while
(or a `while`, because Python) to ensure that the returned secret key is
secure.
--
Comment:
I don't think it's worth complexity, if someone will hit such secret they
should buy a lottery ticket and regenerate a secret key.
--
Ticket URL: <https://code.djangoproject.com/ticket/32327#comment:2>