Skip to content

[P1] Reject empty session and server secrets #50

Description

@michielbdejong

Recorded during review of main at a1eb305ccfa2f3fc8ddede4875765cf1b099bd2b. This issue records a finding only; no implementation changes were made or requested.

Finding

SESSION_SECRET= is treated as a configured secret and hashed into a reproducible cookie-encryption key, rather than triggering random key generation. SERVER_SECRET= is also accepted. Both are blank in the example configuration. Empty values can therefore undermine session authentication and tenant-secret derivation.

Evidence

Desired outcome

Reject empty required secrets. Treat an empty optional session secret as absent or fail configuration explicitly. Add configuration checks for absent, empty, and valid values.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions