Session security already comes from a cryptographically random 256-bit token (secrets.token_urlsafe) hashed before storage — SESSION_SECRET was required config that nothing ever read.
339 B
339 B