Recorded during review of main at a1eb305ccfa2f3fc8ddede4875765cf1b099bd2b. This issue records a finding only; no implementation changes were made or requested.
Finding
SESSION_SECRET= is treated as a configured secret and hashed into a reproducible cookie-encryption key, rather than triggering random key generation. SERVER_SECRET= is also accepted. Both are blank in the example configuration. Empty values can therefore undermine session authentication and tenant-secret derivation.
Evidence
Desired outcome
Reject empty required secrets. Treat an empty optional session secret as absent or fail configuration explicitly. Add configuration checks for absent, empty, and valid values.
Recorded during review of main at
a1eb305ccfa2f3fc8ddede4875765cf1b099bd2b. This issue records a finding only; no implementation changes were made or requested.Finding
SESSION_SECRET=is treated as a configured secret and hashed into a reproducible cookie-encryption key, rather than triggering random key generation.SERVER_SECRET=is also accepted. Both are blank in the example configuration. Empty values can therefore undermine session authentication and tenant-secret derivation.Evidence
Desired outcome
Reject empty required secrets. Treat an empty optional session secret as absent or fail configuration explicitly. Add configuration checks for absent, empty, and valid values.