fix: remove unused SESSION_SECRET config

Session security already comes from a cryptographically random
256-bit token (secrets.token_urlsafe) hashed before storage —
SESSION_SECRET was required config that nothing ever read.
This commit is contained in:
Indiana
2026-07-21 03:43:08 +00:00
parent 0756e677b9
commit d2f4c0a993
4 changed files with 2 additions and 7 deletions

View File

@@ -129,7 +129,7 @@ sudo -u postgres psql -c "CREATE DATABASE quantumancy_test OWNER quantumancy ENC
```bash
cp .env.example .env
# edit .env: set a real SESSION_SECRET, confirm DATABASE_URL and OLLAMA_BASE_URL
# edit .env: confirm DATABASE_URL and OLLAMA_BASE_URL
```
**3. Backend:**
@@ -198,13 +198,12 @@ Any Ollama tag works — override with `OLLAMA_FAST_MODEL` / `OLLAMA_CHAT_MODEL`
All settings live in `backend/app/config.py` and are read from the environment
or `.env` (repo root when run via systemd; CWD otherwise). Required:
`DATABASE_URL`, `OLLAMA_BASE_URL`, `SESSION_SECRET`.
`DATABASE_URL`, `OLLAMA_BASE_URL`.
| Env var | Default | Purpose |
|---|---|---|
| `DATABASE_URL` | — | asyncpg connection string, e.g. `postgresql+asyncpg://quantumancy:quantumancy@localhost:5432/quantumancy` |
| `OLLAMA_BASE_URL` | — | Ollama REST endpoint, e.g. `http://10.30.20.107:11434` |
| `SESSION_SECRET` | — | random 64-char string (session cookie signing) |
| `PORT` | `7777` | HTTP listen port |
| `OLLAMA_FAST_MODEL` | `granite4.1:3b` | fast tier: fragments, wire whispers |
| `OLLAMA_CHAT_MODEL` | `minicpm-v4.5:latest` | chat tier: direct contact, entity minting |
@@ -268,7 +267,6 @@ dropped and recreated on every run):
cd backend && source venv/bin/activate
DATABASE_URL=postgresql+asyncpg://quantumancy:quantumancy@localhost:5432/quantumancy_test \
OLLAMA_BASE_URL=http://10.30.20.107:11434 \
SESSION_SECRET=test-secret \
python -m pytest -v
```