fix: remove unused SESSION_SECRET config

Session security already comes from a cryptographically random
256-bit token (secrets.token_urlsafe) hashed before storage —
SESSION_SECRET was required config that nothing ever read.
This commit is contained in:
Indiana
2026-07-21 03:43:08 +00:00
parent 0756e677b9
commit d2f4c0a993
4 changed files with 2 additions and 7 deletions

View File

@@ -1,6 +1,5 @@
DATABASE_URL=postgresql+asyncpg://quantumancy:quantumancy@localhost:5432/quantumancy DATABASE_URL=postgresql+asyncpg://quantumancy:quantumancy@localhost:5432/quantumancy
OLLAMA_BASE_URL=http://10.30.20.107:11434 OLLAMA_BASE_URL=http://10.30.20.107:11434
SESSION_SECRET=change-me-to-a-random-64-char-string
PORT=7777 PORT=7777
# LLM tiers on the Ollama box (fast = fragments/ambient, chat = direct contact/minting) # LLM tiers on the Ollama box (fast = fragments/ambient, chat = direct contact/minting)
OLLAMA_FAST_MODEL=granite4.1:3b OLLAMA_FAST_MODEL=granite4.1:3b

View File

@@ -129,7 +129,7 @@ sudo -u postgres psql -c "CREATE DATABASE quantumancy_test OWNER quantumancy ENC
```bash ```bash
cp .env.example .env cp .env.example .env
# edit .env: set a real SESSION_SECRET, confirm DATABASE_URL and OLLAMA_BASE_URL # edit .env: confirm DATABASE_URL and OLLAMA_BASE_URL
``` ```
**3. Backend:** **3. Backend:**
@@ -198,13 +198,12 @@ Any Ollama tag works — override with `OLLAMA_FAST_MODEL` / `OLLAMA_CHAT_MODEL`
All settings live in `backend/app/config.py` and are read from the environment All settings live in `backend/app/config.py` and are read from the environment
or `.env` (repo root when run via systemd; CWD otherwise). Required: or `.env` (repo root when run via systemd; CWD otherwise). Required:
`DATABASE_URL`, `OLLAMA_BASE_URL`, `SESSION_SECRET`. `DATABASE_URL`, `OLLAMA_BASE_URL`.
| Env var | Default | Purpose | | Env var | Default | Purpose |
|---|---|---| |---|---|---|
| `DATABASE_URL` | — | asyncpg connection string, e.g. `postgresql+asyncpg://quantumancy:quantumancy@localhost:5432/quantumancy` | | `DATABASE_URL` | — | asyncpg connection string, e.g. `postgresql+asyncpg://quantumancy:quantumancy@localhost:5432/quantumancy` |
| `OLLAMA_BASE_URL` | — | Ollama REST endpoint, e.g. `http://10.30.20.107:11434` | | `OLLAMA_BASE_URL` | — | Ollama REST endpoint, e.g. `http://10.30.20.107:11434` |
| `SESSION_SECRET` | — | random 64-char string (session cookie signing) |
| `PORT` | `7777` | HTTP listen port | | `PORT` | `7777` | HTTP listen port |
| `OLLAMA_FAST_MODEL` | `granite4.1:3b` | fast tier: fragments, wire whispers | | `OLLAMA_FAST_MODEL` | `granite4.1:3b` | fast tier: fragments, wire whispers |
| `OLLAMA_CHAT_MODEL` | `minicpm-v4.5:latest` | chat tier: direct contact, entity minting | | `OLLAMA_CHAT_MODEL` | `minicpm-v4.5:latest` | chat tier: direct contact, entity minting |
@@ -268,7 +267,6 @@ dropped and recreated on every run):
cd backend && source venv/bin/activate cd backend && source venv/bin/activate
DATABASE_URL=postgresql+asyncpg://quantumancy:quantumancy@localhost:5432/quantumancy_test \ DATABASE_URL=postgresql+asyncpg://quantumancy:quantumancy@localhost:5432/quantumancy_test \
OLLAMA_BASE_URL=http://10.30.20.107:11434 \ OLLAMA_BASE_URL=http://10.30.20.107:11434 \
SESSION_SECRET=test-secret \
python -m pytest -v python -m pytest -v
``` ```

View File

@@ -6,7 +6,6 @@ class Settings(BaseSettings):
database_url: str database_url: str
ollama_base_url: str ollama_base_url: str
session_secret: str
port: int = 7777 port: int = 7777
# LLM tiers — CPU-only remote Ollama, so the fast tier must stay small. # LLM tiers — CPU-only remote Ollama, so the fast tier must stay small.

View File

@@ -4,7 +4,6 @@ from app.config import Settings
def test_settings_load_from_env(monkeypatch): def test_settings_load_from_env(monkeypatch):
monkeypatch.setenv("DATABASE_URL", "postgresql+asyncpg://u:p@host/db") monkeypatch.setenv("DATABASE_URL", "postgresql+asyncpg://u:p@host/db")
monkeypatch.setenv("OLLAMA_BASE_URL", "http://10.30.20.107:11434") monkeypatch.setenv("OLLAMA_BASE_URL", "http://10.30.20.107:11434")
monkeypatch.setenv("SESSION_SECRET", "test-secret")
settings = Settings(_env_file=None) settings = Settings(_env_file=None)
assert settings.database_url == "postgresql+asyncpg://u:p@host/db" assert settings.database_url == "postgresql+asyncpg://u:p@host/db"
assert settings.ollama_base_url == "http://10.30.20.107:11434" assert settings.ollama_base_url == "http://10.30.20.107:11434"