Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #207925 > unrolled thread

Request for a Good Practice for webdev doc.

Started byaprekates <aprekates@posteo.net>
First post2019-04-28 18:50 +0200
Last post2019-05-02 08:20 +0200
Articles 7 — 6 participants

Back to article view | Back to linux.debian.user


Contents

  Request for a Good Practice for webdev doc. aprekates <aprekates@posteo.net> - 2019-04-28 18:50 +0200
    Re: Request for a Good Practice for webdev doc. deloptes <deloptes@gmail.com> - 2019-04-28 20:20 +0200
      Re: Request for a Good Practice for webdev doc. Richard Owlett <rowlett@cloud85.net> - 2019-04-28 21:10 +0200
        Re: Request for a Good Practice for webdev doc. Brian <ad44@cityscape.co.uk> - 2019-04-28 21:40 +0200
          Re: Request for a Good Practice for webdev doc. Richard Owlett <rowlett@cloud85.net> - 2019-04-28 21:50 +0200
        Re: Request for a Good Practice for webdev doc. David Wright <deblis@lionunicorn.co.uk> - 2019-05-02 05:40 +0200
    Re: Request for a Good Practice for webdev doc. "Alexander V. Makartsev" <avbetev@gmail.com> - 2019-05-02 08:20 +0200

#207925 — Request for a Good Practice for webdev doc.

Fromaprekates <aprekates@posteo.net>
Date2019-04-28 18:50 +0200
SubjectRequest for a Good Practice for webdev doc.
Message-ID<xRVa1-7oP-3@gated-at.bofh.it>
Experimenting with wsgi and python webapp dev
i came upon issues and roads to choose mainly
regarding to installation , deployment and security
related issues.

sudo pip install ..   or  pip install

is virtualenv secure or is just redicect trickery and
not a real chroot enviroment ?

Should i make another user for developement ?

I think by a little search to the net around similar questions thats
a doc from the community , endorsing some good practices for
developers could be of help.

I've read 
https://wiki.debian.org/DontBreakDebian#Using_chroot.2C_containers.2C_and_virtual_machines
but i thinks there are more questions.

Thanks.

[toc] | [next] | [standalone]


#207935

Fromdeloptes <deloptes@gmail.com>
Date2019-04-28 20:20 +0200
Message-ID<xRWz7-8mn-5@gated-at.bofh.it>
In reply to#207925
aprekates wrote:

> Experimenting with wsgi and python webapp dev
> i came upon issues and roads to choose mainly
> regarding to installation , deployment and security
> related issues.
> 
> sudo pip install ..   or  pip install
> 

don't work as root if not necessary

> is virtualenv secure or is just redicect trickery and
> not a real chroot enviroment ?
> 

I personally prefer this. I don't want to mess up my work environment - this
stays clean and stable. I use chroot if possible, if not virtual machine or
emulator. I have also few test devices around, before putting things in
production.

> Should i make another user for developement ?
> 

The least you could do - but still all depends what you want to do.
Development is not dangerous thing - more dangerous is deploying untested
software.

> I think by a little search to the net around similar questions thats
> a doc from the community , endorsing some good practices for
> developers could be of help.
> 
> I've read
>
https://wiki.debian.org/DontBreakDebian#Using_chroot.2C_containers.2C_and_virtual_machines
> but i thinks there are more questions.

Ask and you will be answered. Perhaps consider subscribing the list that
will deliver the answers - this here is general debian user list. It is not
for python or for development. Although we share thoughts on all
(meaningful) topics.

regards

[toc] | [prev] | [next] | [standalone]


#207942

FromRichard Owlett <rowlett@cloud85.net>
Date2019-04-28 21:10 +0200
Message-ID<xRXlv-pT-3@gated-at.bofh.it>
In reply to#207935
On 04/28/2019 01:17 PM, deloptes wrote:
>> [*SNIP*]
>> I've read
>> [ URL deleted to focus on wider issue]
>> but i thinks there are more questions.

Short answer: MANY**MULTITUDINOUS   ;/

> 
> Ask and you will be answered.

On debian-user ???

> Perhaps consider subscribing the list that will deliver the answers

How to find such a list?
Case in point - I wish to explore "corner cases".
[ otherwise known in 'universal advice' as "DON'T do dat" ]

{To clarify - DON'T *EVER* try my questions on a system on which you 
depend!!!!!!!!!!!!!!!!!!!!!!!!!!!}

Back to my point -- is there a list aimed at experimenters ?
[ especially one which recognizes that experiments ~= *FAIL*
   and potential rewards are worth the GRIEF]

OWL hereby DUCKS fer cover ;/

[toc] | [prev] | [next] | [standalone]


#207943

FromBrian <ad44@cityscape.co.uk>
Date2019-04-28 21:40 +0200
Message-ID<xRXOy-zs-19@gated-at.bofh.it>
In reply to#207942
On Sun 28 Apr 2019 at 14:07:32 -0500, Richard Owlett wrote:

> On 04/28/2019 01:17 PM, deloptes wrote:
> > > [*SNIP*]
> > > I've read
> > > [ URL deleted to focus on wider issue]
> > > but i thinks there are more questions.
> 
> Short answer: MANY**MULTITUDINOUS   ;/
> 
> > 
> > Ask and you will be answered.
> 
> On debian-user ???
 
This really does point up your piss artist status. Over the years you
have had your many questions assiduously addressed. If your needs were
not met, that has more to do with "I want to do it my way".

> > Perhaps consider subscribing the list that will deliver the answers
> 
> How to find such a list?
> Case in point - I wish to explore "corner cases".
> [ otherwise known in 'universal advice' as "DON'T do dat" ]

In the immortal words of Linus - bollocks.
> 
> {To clarify - DON'T *EVER* try my questions on a system on which you
> depend!!!!!!!!!!!!!!!!!!!!!!!!!!!}

Even the exclamation marks do not convey any sense here.

> Back to my point -- is there a list aimed at experimenters ?
> [ especially one which recognizes that experiments ~= *FAIL*
>   and potential rewards are worth the GRIEF]
> 
> OWL hereby DUCKS fer cover ;/

Under a stone?

-- 
Brian.

[toc] | [prev] | [next] | [standalone]


#207945

FromRichard Owlett <rowlett@cloud85.net>
Date2019-04-28 21:50 +0200
Message-ID<xRXYd-CU-3@gated-at.bofh.it>
In reply to#207943
On 04/28/2019 02:31 PM, Brian wrote:
null set

Someday he may actually read posts with which he disagrees

What is sad is that he has, in past, demonstrated technical competency.
Therefor he has not been *PLONKED*

I will continue to read his responses.
It is unlikely that I will respond.

Will he grow up?

[toc] | [prev] | [next] | [standalone]


#208023

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2019-05-02 05:40 +0200
Message-ID<xTaJH-4Pk-9@gated-at.bofh.it>
In reply to#207942
On Sun 28 Apr 2019 at 14:07:32 (-0500), Richard Owlett wrote:
> On 04/28/2019 01:17 PM, deloptes wrote:
> > > [*SNIP*]
> > > I've read
> > > [ URL deleted to focus on wider issue]
> > > but i thinks there are more questions.
> 
> Short answer: MANY**MULTITUDINOUS   ;/
> 
> > 
> > Ask and you will be answered.
> 
> On debian-user ???
> 
> > Perhaps consider subscribing the list that will deliver the answers
> 
> How to find such a list?
> Case in point - I wish to explore "corner cases".
> [ otherwise known in 'universal advice' as "DON'T do dat" ]
> 
> {To clarify - DON'T *EVER* try my questions on a system on which you
> depend!!!!!!!!!!!!!!!!!!!!!!!!!!!}
> 
> Back to my point -- is there a list aimed at experimenters ?

For that to work, you have to be prepared to share your goals, and the
results of your experiments, in a spirit of cooperation.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#208025

From"Alexander V. Makartsev" <avbetev@gmail.com>
Date2019-05-02 08:20 +0200
Message-ID<xTdex-6uh-3@gated-at.bofh.it>
In reply to#207925

[Multipart message — attachments visible in raw view] — view raw

On 28.04.2019 21:42, aprekates wrote:
> Experimenting with wsgi and python webapp dev
> i came upon issues and roads to choose mainly
> regarding to installation , deployment and security
> related issues.
>
> sudo pip install ..   or  pip install
>
> is virtualenv secure or is just redicect trickery and
> not a real chroot enviroment ?
>
> Should i make another user for developement ?
>
> I think by a little search to the net around similar questions thats
> a doc from the community , endorsing some good practices for
> developers could be of help.
>
> I've read
> https://wiki.debian.org/DontBreakDebian#Using_chroot.2C_containers.2C_and_virtual_machines
> but i thinks there are more questions.
>
> Thanks.
>
>
I think it is a good practice in general to actually test if something
bothers you.
You can setup your virtualenv environment by the book in test VM, and
create deliberately insecure python webapp to test how virtualenv will
behave if you try to
execute shell commands from a web-browser, try to steal passwords,
execute SQL commands, read, write, execute arbitrary files, etc.
Check out what username is used when you will do all that, what
limitations and what options available for it.
If your system will host a few websites (Virtual Hosts), test if you can
access the information on any of them from another website or not.
This way you can see how good the isolation is and its limitations and
how to fix it and improve it.

WebDev IMO is hell with all those pip-s and npm-s out there pushing
packages and modules and dependencies into your environment and you have
to audit their code by yourself or blindly trust they are safe.
You should read the documentation, research and test to get the answers
for the every question you have. Understand how everything works internally.
There are no step-by-step guides for security topics, because everything
could be setup in myriad ways, constantly evolving and becoming so
complex that there is almost never a straight answer for anything.

-- 
With kindest regards, Alexander.

⢀⣴⠾⠻⢶⣦⠀ 
⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org
⠈⠳⣄⠀⠀⠀⠀ 

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web