fix: remove unused SESSION_SECRET config

Session security already comes from a cryptographically random
256-bit token (secrets.token_urlsafe) hashed before storage —
SESSION_SECRET was required config that nothing ever read.
This commit is contained in:
Indiana
2026-07-21 03:43:08 +00:00
parent 0756e677b9
commit d2f4c0a993
4 changed files with 2 additions and 7 deletions

View File

@@ -6,7 +6,6 @@ class Settings(BaseSettings):
database_url: str
ollama_base_url: str
session_secret: str
port: int = 7777
# LLM tiers — CPU-only remote Ollama, so the fast tier must stay small.

View File

@@ -4,7 +4,6 @@ from app.config import Settings
def test_settings_load_from_env(monkeypatch):
monkeypatch.setenv("DATABASE_URL", "postgresql+asyncpg://u:p@host/db")
monkeypatch.setenv("OLLAMA_BASE_URL", "http://10.30.20.107:11434")
monkeypatch.setenv("SESSION_SECRET", "test-secret")
settings = Settings(_env_file=None)
assert settings.database_url == "postgresql+asyncpg://u:p@host/db"
assert settings.ollama_base_url == "http://10.30.20.107:11434"