From d2f4c0a9938eef04173714ba1a6dec073dbbd00e Mon Sep 17 00:00:00 2001 From: Indiana Date: Tue, 21 Jul 2026 03:43:08 +0000 Subject: [PATCH] fix: remove unused SESSION_SECRET config MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Session security already comes from a cryptographically random 256-bit token (secrets.token_urlsafe) hashed before storage — SESSION_SECRET was required config that nothing ever read. --- .env.example | 1 - README.md | 6 ++---- backend/app/config.py | 1 - backend/tests/test_config.py | 1 - 4 files changed, 2 insertions(+), 7 deletions(-) diff --git a/.env.example b/.env.example index f6a28ef..18e473b 100644 --- a/.env.example +++ b/.env.example @@ -1,6 +1,5 @@ DATABASE_URL=postgresql+asyncpg://quantumancy:quantumancy@localhost:5432/quantumancy OLLAMA_BASE_URL=http://10.30.20.107:11434 -SESSION_SECRET=change-me-to-a-random-64-char-string PORT=7777 # LLM tiers on the Ollama box (fast = fragments/ambient, chat = direct contact/minting) OLLAMA_FAST_MODEL=granite4.1:3b diff --git a/README.md b/README.md index 4949a13..6c68664 100644 --- a/README.md +++ b/README.md @@ -129,7 +129,7 @@ sudo -u postgres psql -c "CREATE DATABASE quantumancy_test OWNER quantumancy ENC ```bash cp .env.example .env -# edit .env: set a real SESSION_SECRET, confirm DATABASE_URL and OLLAMA_BASE_URL +# edit .env: confirm DATABASE_URL and OLLAMA_BASE_URL ``` **3. Backend:** @@ -198,13 +198,12 @@ Any Ollama tag works — override with `OLLAMA_FAST_MODEL` / `OLLAMA_CHAT_MODEL` All settings live in `backend/app/config.py` and are read from the environment or `.env` (repo root when run via systemd; CWD otherwise). Required: -`DATABASE_URL`, `OLLAMA_BASE_URL`, `SESSION_SECRET`. +`DATABASE_URL`, `OLLAMA_BASE_URL`. | Env var | Default | Purpose | |---|---|---| | `DATABASE_URL` | — | asyncpg connection string, e.g. `postgresql+asyncpg://quantumancy:quantumancy@localhost:5432/quantumancy` | | `OLLAMA_BASE_URL` | — | Ollama REST endpoint, e.g. `http://10.30.20.107:11434` | -| `SESSION_SECRET` | — | random 64-char string (session cookie signing) | | `PORT` | `7777` | HTTP listen port | | `OLLAMA_FAST_MODEL` | `granite4.1:3b` | fast tier: fragments, wire whispers | | `OLLAMA_CHAT_MODEL` | `minicpm-v4.5:latest` | chat tier: direct contact, entity minting | @@ -268,7 +267,6 @@ dropped and recreated on every run): cd backend && source venv/bin/activate DATABASE_URL=postgresql+asyncpg://quantumancy:quantumancy@localhost:5432/quantumancy_test \ OLLAMA_BASE_URL=http://10.30.20.107:11434 \ -SESSION_SECRET=test-secret \ python -m pytest -v ``` diff --git a/backend/app/config.py b/backend/app/config.py index 47c525f..5112374 100644 --- a/backend/app/config.py +++ b/backend/app/config.py @@ -6,7 +6,6 @@ class Settings(BaseSettings): database_url: str ollama_base_url: str - session_secret: str port: int = 7777 # LLM tiers — CPU-only remote Ollama, so the fast tier must stay small. diff --git a/backend/tests/test_config.py b/backend/tests/test_config.py index 0c4d628..97ee0a7 100644 --- a/backend/tests/test_config.py +++ b/backend/tests/test_config.py @@ -4,7 +4,6 @@ from app.config import Settings def test_settings_load_from_env(monkeypatch): monkeypatch.setenv("DATABASE_URL", "postgresql+asyncpg://u:p@host/db") monkeypatch.setenv("OLLAMA_BASE_URL", "http://10.30.20.107:11434") - monkeypatch.setenv("SESSION_SECRET", "test-secret") settings = Settings(_env_file=None) assert settings.database_url == "postgresql+asyncpg://u:p@host/db" assert settings.ollama_base_url == "http://10.30.20.107:11434"