fix: remove unused SESSION_SECRET config
Session security already comes from a cryptographically random 256-bit token (secrets.token_urlsafe) hashed before storage — SESSION_SECRET was required config that nothing ever read.
This commit is contained in:
@@ -129,7 +129,7 @@ sudo -u postgres psql -c "CREATE DATABASE quantumancy_test OWNER quantumancy ENC
|
||||
|
||||
```bash
|
||||
cp .env.example .env
|
||||
# edit .env: set a real SESSION_SECRET, confirm DATABASE_URL and OLLAMA_BASE_URL
|
||||
# edit .env: confirm DATABASE_URL and OLLAMA_BASE_URL
|
||||
```
|
||||
|
||||
**3. Backend:**
|
||||
@@ -198,13 +198,12 @@ Any Ollama tag works — override with `OLLAMA_FAST_MODEL` / `OLLAMA_CHAT_MODEL`
|
||||
|
||||
All settings live in `backend/app/config.py` and are read from the environment
|
||||
or `.env` (repo root when run via systemd; CWD otherwise). Required:
|
||||
`DATABASE_URL`, `OLLAMA_BASE_URL`, `SESSION_SECRET`.
|
||||
`DATABASE_URL`, `OLLAMA_BASE_URL`.
|
||||
|
||||
| Env var | Default | Purpose |
|
||||
|---|---|---|
|
||||
| `DATABASE_URL` | — | asyncpg connection string, e.g. `postgresql+asyncpg://quantumancy:quantumancy@localhost:5432/quantumancy` |
|
||||
| `OLLAMA_BASE_URL` | — | Ollama REST endpoint, e.g. `http://10.30.20.107:11434` |
|
||||
| `SESSION_SECRET` | — | random 64-char string (session cookie signing) |
|
||||
| `PORT` | `7777` | HTTP listen port |
|
||||
| `OLLAMA_FAST_MODEL` | `granite4.1:3b` | fast tier: fragments, wire whispers |
|
||||
| `OLLAMA_CHAT_MODEL` | `minicpm-v4.5:latest` | chat tier: direct contact, entity minting |
|
||||
@@ -268,7 +267,6 @@ dropped and recreated on every run):
|
||||
cd backend && source venv/bin/activate
|
||||
DATABASE_URL=postgresql+asyncpg://quantumancy:quantumancy@localhost:5432/quantumancy_test \
|
||||
OLLAMA_BASE_URL=http://10.30.20.107:11434 \
|
||||
SESSION_SECRET=test-secret \
|
||||
python -m pytest -v
|
||||
```
|
||||
|
||||
|
||||
Reference in New Issue
Block a user