diff --git a/lib/galaxy/config.py b/lib/galaxy/config.py index 4b5110ec10c..30c04b8824d 100644 --- a/lib/galaxy/config.py +++ b/lib/galaxy/config.py @@ -35,6 +35,9 @@ class Configuration( object ): self.test_conf = resolve_path( kwargs.get( "test_conf", "" ), self.root ) self.tool_config = resolve_path( kwargs.get( 'tool_config_file', 'tool_conf.xml' ), self.root ) self.tool_secret = kwargs.get( "tool_secret", "" ) + # CRITICAL: the value of id_secret MUST be the same in universe_wsgi.ini and reports_wsgi.ini + # or the framework's __ensure_valid_session method will throw exceptions when switching between + # Galaxy and the reports in the same browser. self.id_secret = kwargs.get( "id_secret", "USING THE DEFAULT IS NOT SECURE!" ) self.use_remote_user = string_as_bool( kwargs.get( "use_remote_user", "False" ) ) self.remote_user_maildomain = kwargs.get( "remote_user_maildomain", None ) diff --git a/lib/galaxy/webapps/reports/config.py b/lib/galaxy/webapps/reports/config.py index 57500c32450..0a13762bfd2 100644 --- a/lib/galaxy/webapps/reports/config.py +++ b/lib/galaxy/webapps/reports/config.py @@ -25,14 +25,14 @@ class Configuration( object ): # Where dataset files are stored self.file_path = resolve_path( kwargs.get( "file_path", "database/files" ), self.root ) self.new_file_path = resolve_path( kwargs.get( "new_file_path", "database/tmp" ), self.root ) + # CRITICAL: the value of id_secret MUST be the same in universe_wsgi.ini and reports_wsgi.ini + # or the framework's __ensure_valid_session method will throw exceptions when switching between + # Galaxy and the reports in the same browser. self.id_secret = kwargs.get( "id_secret", "USING THE DEFAULT IS NOT SECURE!" ) self.use_remote_user = string_as_bool( kwargs.get( "use_remote_user", "False" ) ) self.template_path = resolve_path( kwargs.get( "template_path", "templates" ), self.root ) self.template_cache = resolve_path( kwargs.get( "template_cache_path", "database/reports/compiled_templates" ), self.root ) - self.admin_pass = kwargs.get('admin_pass',"galaxy") self.sendmail_path = kwargs.get('sendmail_path',"/usr/sbin/sendmail") - self.mailing_join_addr = kwargs.get('mailing_join_addr',"galaxy-user-join@bx.psu.edu") - self.error_email_to = kwargs.get( 'error_email_to', None ) self.brand = kwargs.get( 'brand', None ) self.wiki_url = kwargs.get( 'wiki_url', "http://g2.trac.bx.psu.edu/" ) self.bugs_email = kwargs.get( 'bugs_email', "mailto:galaxy-bugs@bx.psu.edu" ) diff --git a/reports_wsgi.ini.sample b/reports_wsgi.ini.sample index d95314bdae8..9c45ff1294d 100644 --- a/reports_wsgi.ini.sample +++ b/reports_wsgi.ini.sample @@ -36,6 +36,10 @@ session_data_dir = %(here)s/database/beaker_sessions session_key = galaxysessions session_secret = changethisinproduction +# Galaxy session security +# The value of id_secret MUST be the same as the value of id_secret in universe_wsgi.ini +id_secret = changethisinproductiontoo + # Configuration for debugging middleware debug = true use_lint = false @@ -43,9 +47,6 @@ use_lint = false # NEVER enable this on a public site (even test or QA) # use_interactive = true -# Admin Password -admin_pass = "galaxy" - # path to sendmail sendmail_path = /usr/sbin/sendmail @@ -58,10 +59,6 @@ mailing_join_addr = galaxy-user-join@bx.psu.edu # Profiling middleware (cProfile based) ## use_profile = True -# Mail -smtp_server = coltrane.bx.psu.edu -error_email_to = galaxy_bugs@bx.psu.edu - # Use the new iframe / javascript based layout use_new_layout = true diff --git a/universe_wsgi.ini.sample b/universe_wsgi.ini.sample index 4208bdb8f05..732de871182 100644 --- a/universe_wsgi.ini.sample +++ b/universe_wsgi.ini.sample @@ -73,6 +73,7 @@ session_key = galaxysessions session_secret = changethisinproduction # Galaxy session security +# The value of id_secret MUST be the same as the value of id_secret in reports_wsgi.ini id_secret = changethisinproductiontoo # Use user provided in an upstream server's $REMOTE_USER variable