Commit f802d3b
committed
security: remove hardcoded passwords from test configuration
Removed hardcoded authentication credentials from docker-compose.test.yml
in response to GitGuardian security warning. Test services now run without
authentication for local testing only.
## Changes
### docker-compose.test.yml
- Removed MongoDB username/password (test_admin/test_password)
- Removed Redis password (test_redis_password)
- Simplified AWS credentials to "test/test" placeholders
- Added security warning header to file
- Added comments clarifying local-only usage
### tests/conftest.py
- Updated S3 client defaults to use "test/test" credentials
- Added security comment for LocalStack credentials
### tests/integration/README.md
- Updated environment variable examples to remove passwords
- Changed MongoDB URI from authenticated to non-authenticated
- Changed Redis URL to remove password
- Updated AWS credentials to simpler "test/test" placeholders
- Added security notice warning against production use
- Updated Redis troubleshooting command to remove password flag
## Security Rationale
For LOCAL TESTING ONLY:
- No real data or secrets involved
- Services bind to localhost only
- Simplifies local development workflow
- Reduces false positives from security scanners
- All credentials are placeholders that never touch real services
**Production deployments must use proper authentication and secrets management.**
Fixes GitGuardian security warning1 parent 32106b9 commit f802d3b
File tree
3 files changed
+35
-19
lines changed- apps/backend
- tests
- integration
3 files changed
+35
-19
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
3 | 9 | | |
4 | 10 | | |
| 11 | + | |
| 12 | + | |
5 | 13 | | |
6 | 14 | | |
7 | 15 | | |
8 | 16 | | |
9 | 17 | | |
10 | 18 | | |
11 | | - | |
12 | | - | |
13 | 19 | | |
14 | 20 | | |
15 | 21 | | |
| |||
22 | 28 | | |
23 | 29 | | |
24 | 30 | | |
| 31 | + | |
| 32 | + | |
25 | 33 | | |
26 | 34 | | |
27 | 35 | | |
28 | 36 | | |
29 | 37 | | |
30 | | - | |
| 38 | + | |
31 | 39 | | |
32 | 40 | | |
33 | 41 | | |
| |||
38 | 46 | | |
39 | 47 | | |
40 | 48 | | |
41 | | - | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
42 | 52 | | |
43 | 53 | | |
44 | 54 | | |
| |||
50 | 60 | | |
51 | 61 | | |
52 | 62 | | |
53 | | - | |
54 | | - | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
55 | 66 | | |
56 | 67 | | |
57 | 68 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
284 | 284 | | |
285 | 285 | | |
286 | 286 | | |
| 287 | + | |
287 | 288 | | |
288 | | - | |
289 | | - | |
| 289 | + | |
| 290 | + | |
290 | 291 | | |
291 | 292 | | |
292 | 293 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
33 | 33 | | |
34 | 34 | | |
35 | 35 | | |
36 | | - | |
| 36 | + | |
37 | 37 | | |
38 | 38 | | |
39 | | - | |
40 | | - | |
| 39 | + | |
| 40 | + | |
41 | 41 | | |
42 | 42 | | |
43 | | - | |
44 | | - | |
| 43 | + | |
| 44 | + | |
45 | 45 | | |
46 | | - | |
47 | | - | |
48 | | - | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
49 | 50 | | |
50 | 51 | | |
51 | 52 | | |
52 | | - | |
| 53 | + | |
53 | 54 | | |
54 | 55 | | |
55 | 56 | | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
56 | 60 | | |
57 | 61 | | |
58 | 62 | | |
| |||
183 | 187 | | |
184 | 188 | | |
185 | 189 | | |
186 | | - | |
187 | | - | |
| 190 | + | |
| 191 | + | |
188 | 192 | | |
189 | 193 | | |
190 | 194 | | |
| |||
0 commit comments