Making sure debug is off in production
Over a year ago I wrote about turning debug off automatically in production. That post I wrote is completely wrong (to an extent). The theory is correct but the execution was incorrect. Even one of the comments pointed out the problem, but I haven't had time to blog about it till now.
About a month ago I realized my implementation was wrong when one of my live sites was outputting MySQL errors and database information (including passwords) to all my users. Since debug in core.php was set to 2, and then disabled to 0 in bootstrap.php, the errors were being triggered before bootstrap was loaded. This was a huge problem as it printed out vital DB information.
It is an easy fix however, simply switch around the values from my previous entry. Debug in core.php should be set to 0 and in bootstrap.php it should be set to 2! That fixes the startup errors that appear before the bootstrap process.
if (env('REMOTE_ADDR') == '127.0.0.1') {
Configure::write('debug', 2);
}
5 Comments
Create a __construct() function in your DATABASE_CONFIG class (in config/database.php) and do something like:
Another issue we had is the comparison with 127.0.0.1. The problem is: is you access the app via intranet you wont be able to the the debug information, something you need if you are working in a team. The way we solve it was setting virtual hosts and comparing to that, for example
Thanks for your post and opening this discussion!
This is what I use for testing and deploying sites.
It also means I can use debugging for my public IP address for a live site, while the rest of the world is served with debug set at 0.
Enjoy.