2 Commits

Author SHA1 Message Date
Indiana
d2f4c0a993 fix: remove unused SESSION_SECRET config
Session security already comes from a cryptographically random
256-bit token (secrets.token_urlsafe) hashed before storage —
SESSION_SECRET was required config that nothing ever read.
2026-07-21 03:43:08 +00:00
Indiana
9e69c622c9 feat: add settings and async db engine 2026-07-20 15:01:25 +00:00