fix: remove unused SESSION_SECRET config
Session security already comes from a cryptographically random 256-bit token (secrets.token_urlsafe) hashed before storage — SESSION_SECRET was required config that nothing ever read.
This commit is contained in:
@@ -6,7 +6,6 @@ class Settings(BaseSettings):
|
||||
|
||||
database_url: str
|
||||
ollama_base_url: str
|
||||
session_secret: str
|
||||
port: int = 7777
|
||||
|
||||
# LLM tiers — CPU-only remote Ollama, so the fast tier must stay small.
|
||||
|
||||
Reference in New Issue
Block a user