You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Flask+SQLite3应用部署后数据库权限安全解决方案问询

How to Securely Enable SQLite Writes for Your Flask App on Ubuntu

Hey there! I totally get why you reached for chmod 777 to fix that read-only database error—it’s a quick band-aid, but as you noticed, it’s a massive security risk (anyone on the system can read, modify, or delete your user data!). Let’s walk through the proper, secure way to get your Flask app writing to SQLite without exposing your database.

Step 1: Identify the User Running Your Flask App

First, we need to know which user your Flask application is running under. Most common setups (Apache with mod_wsgi, Nginx with uWSGI/Gunicorn) use the www-data user by default. To confirm:

ps aux | grep flask  # Or grep for your web server (apache2, nginx, uwsgi)

Look for the user column next to your app’s process—this is the user that needs write access to the database.

Step 2: Set Correct Ownership for the Database and Directory

SQLite needs write access not just to the .db file, but also to the directory it’s in (it creates temporary journal files there). Run these commands to transfer ownership to the app’s user (we’ll use www-data as the example):

# Change ownership of the database file
sudo chown www-data:www-data /var/www/FlaskApp/database.db

# Change ownership of the parent directory (critical for journaling)
sudo chown www-data:www-data /var/www/FlaskApp

Step 3: Apply Restrictive Permissions

Now set permissions that lock down access to only the necessary user and group:

# Database file: owner can read/write, group can read, others get nothing
sudo chmod 640 /var/www/FlaskApp/database.db

# Parent directory: owner can read/write/execute, group can read/execute, others get nothing
sudo chmod 750 /var/www/FlaskApp

This way, only the www-data user (running your Flask app) can modify the database, and only members of the www-data group can read it—no random users on the system can touch your data.

Bonus Security Tips

  • Move the database out of the web root: For extra safety, relocate database.db to a directory that’s not accessible via the web (e.g., /var/lib/flaskapp/database.db). Update your Flask code’s connection path to match:
    con = sql.connect("/var/lib/flaskapp/database.db")
    
    This prevents attackers from downloading your database file if there’s a misconfiguration in your web server.
  • Keep using parameterized queries: Great job using ? placeholders in your UPDATE statement—this protects against SQL injection attacks, which is another critical security layer.
  • Don’t run your app as root: Ensure your Flask app is always running as a non-privileged user like www-data—running as root gives attackers full system access if your app is compromised.
  • Backup regularly: Schedule periodic backups of your database file (e.g., with cron) so you can recover if something goes wrong.

内容的提问来源于stack exchange,提问作者Dr Simon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 05:18:01