invoiceninja / dockerfiles

Docker files for Invoice Ninja
https://hub.docker.com/r/invoiceninja/invoiceninja
GNU General Public License v2.0
398 stars 264 forks source link

Please don't bind mysql to all interfaces with default credentials in Docker-compose #517

Closed Leopere closed 2 months ago

Leopere commented 1 year ago

Please don't do this. Default credentials on the sql container in the .env file and then bind blindly 3305 on all interfaces for the public to log in with ninja//ninja

ryanwinter commented 2 months ago

What's holding this back from merge? I noticed this immediately when reviewing the docker compose.

Leopere commented 2 months ago

@ryanwinter I can't begin to imagine why you would want to expose your potential user base to such a blatant security misconfiguration that is entirely unnecessary it honestly makes me question how safe this software even is.

This is by far the best software for this task that I can find but woooof that's roouuugh.

turbo124 commented 2 months ago

Thanks!

Leopere commented 2 months ago

y'all rock tyvm <3 I very much appreciate this tool its absolutely the best in class.