Contributors mailing list archives
contributors@odoo-community.org
Browse archives
Re: server_environment_ir_config_parameter security purpose
server_environment_ir_config_parameter security purpose
Re: server_environment_ir_config_parameter security purpose
by
Akretion France., David BEAL
Oops
here is the code
Le lun. 8 juil. 2019 à 17:56, David Beal <david.beal@akretion.com> a écrit :
Hi all,I dived in this moduleI really appreciate to have a way to combine server_env module without to have an UI to build (then a UI fallback). Thanks to the authorsBut I have a question about security or confidentiality of informationsA parameter can be a credential (all that we have in server_env keys), and I ask myself why values contained in server_env filesare always written in ir.config_parameter instead of only used as substitution.IMO, i thought that UI was for demo purposes not for real production storage informations place.These values are also in backup, and that may imply to rise questions in gdpr context I suppose.I think we could have an optionnal behavior to prevent to store data in db.What do you think?Maybe I missed something, so please make me take the right wayOtherwise, I can make a PRThanks for you advicesChef de projetOdoo Développement / Intégration
Reference
-
server_environment_ir_config_parameter security purpose
byAkretion France., David BEAL-
Re: server_environment_ir_config_parameter security purpose
byAkretion France., David BEAL -
Re: server_environment_ir_config_parameter security purpose
byAkretion France., David BEAL
-