Persist a per-install JWT signing secret instead of a compiled-in default.
Format / gofmt (push) Successful in 8s
Format / gofmt (pull_request) Successful in 9s
CI / Build (push) Successful in 24s
CI / Build (pull_request) Successful in 25s
CI / Go Tests (pull_request) Successful in 39s
CI / Go Tests (push) Successful in 40s

Admin tokens were forgeable whenever JWT_SECRET was unset. Prefer the env var, otherwise write a random key to data/.jwt_secret.
This commit is contained in:
s1d3sw1ped_bot
2026-08-31 23:55:34 +00:00
parent 466d69c44c
commit 22844a2a67
6 changed files with 106 additions and 7 deletions
+1
View File
@@ -40,6 +40,7 @@ logs/
*.sqlite-wal
# Keys / secrets
.jwt_secret
keys.json
*.pem
*.key