Lazo Lab Sign up

App 7: Your First Website with Flask / Build a guestbook website

Lesson 9 of 10

Security basics for your site

Turn debug mode off when others can reach the site, load the secret key from an environment variable, add CSRF protection to forms, and keep packages updated.

Key points

  • Never run debug=True in public
  • Secret key from os.environ
  • Flask-WTF adds CSRF tokens
import os
app.secret_key = os.environ["SECRET_KEY"]

Your turn

Move your secret key into an environment variable.

Watch a video on thisOpens YouTube search results for “Security basics for your site” in a new tab

Quiz · +10 XP

Why must debug mode be off on a public site?

Log in to save progress and earn XP.