fix: remove unused SESSION_SECRET config
Session security already comes from a cryptographically random 256-bit token (secrets.token_urlsafe) hashed before storage — SESSION_SECRET was required config that nothing ever read.
This commit is contained in:
@@ -4,7 +4,6 @@ from app.config import Settings
|
||||
def test_settings_load_from_env(monkeypatch):
|
||||
monkeypatch.setenv("DATABASE_URL", "postgresql+asyncpg://u:p@host/db")
|
||||
monkeypatch.setenv("OLLAMA_BASE_URL", "http://10.30.20.107:11434")
|
||||
monkeypatch.setenv("SESSION_SECRET", "test-secret")
|
||||
settings = Settings(_env_file=None)
|
||||
assert settings.database_url == "postgresql+asyncpg://u:p@host/db"
|
||||
assert settings.ollama_base_url == "http://10.30.20.107:11434"
|
||||
|
||||
Reference in New Issue
Block a user