aaronpk / Aperture

Aperture is a Microsub server. Currently in beta.
https://aperture.p3k.io
Apache License 2.0
69 stars 5 forks source link

default APP_DEBUG to false in .env.example #109

Closed martymcguire closed 3 years ago

martymcguire commented 3 years ago

I got dinged by a Laravel debug mode exploit that let an attacker get my .env file with some email-sending credentials. Oops!

I suggest shipping an env example where APP_DEBUG is set to false by default. 😅