App 7: Your First Website with Flask / Build a guestbook website
Lesson 9 of 10
Security basics for your site
Turn debug mode off when others can reach the site, load the secret key from an environment variable, add CSRF protection to forms, and keep packages updated.
Key points
- Never run debug=True in public
- Secret key from os.environ
- Flask-WTF adds CSRF tokens
import os
app.secret_key = os.environ["SECRET_KEY"]Your turn
Move your secret key into an environment variable.
Quiz · +10 XP
Why must debug mode be off on a public site?
Log in to save progress and earn XP.