Persist a per-install JWT signing secret instead of a compiled-in default.
Format / gofmt (push) Successful in 8s
Format / gofmt (pull_request) Successful in 9s
CI / Build (push) Successful in 24s
CI / Build (pull_request) Successful in 25s
CI / Go Tests (pull_request) Successful in 39s
CI / Go Tests (push) Successful in 40s

Admin tokens were forgeable whenever JWT_SECRET was unset. Prefer the env var, otherwise write a random key to data/.jwt_secret.
This commit is contained in:
s1d3sw1ped_bot
2026-08-31 23:55:34 +00:00
parent 466d69c44c
commit 22844a2a67
6 changed files with 106 additions and 7 deletions
+1
View File
@@ -47,6 +47,7 @@ See docker-compose.yml for full example (exposes 80/81/443, volume for data/).
- `data/db.bolt` (or `DATA_DIR`)
- `data/certs/`, `data/logs/`, `data/letsencrypt-acme-challenge/`
- `data/www/` (default site / custom html; `WWW_DIR` or `HTML_DIR`)
- `data/.jwt_secret` (auto-generated admin API signing key if `JWT_SECRET` is unset)
- etc.
## Status