makeplane / makeplane/plane

[bug]: Plane data dir + files are world readable (755)

Open
#9,067 1 comment 0 reactions 2 assignees View on GitHub

@vihar is already working on this.

Since May 13, 2026.

🐛bug plane
Dominant language
TypeScript
Stars
59.6k
Forks
5.8k
Avg merge
1d 22h
Merged PRs (30d)
49

Description

Is there an existing issue for this?
  • I have searched the existing issues
Current behavior

As a regular user running on the machine (or a different service), I can read all plane configs/secrets.

Steps to reproduce
$ id -g
1000
$ cat /opt/plane/plane.env | grep REDIS
# REDIS SETTINGS
REDIS_HOST=plane-redis
REDIS_PORT=6379
REDIS_URL=redis://172.18.0.1:6379
Environment

Production

Browser

None

Variant

Self-hosted

Version

v2.1.0 (prime-cli),

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.