fix(security): remove hardcoded JWT secret fallback - CRITICAL
BREAKING CHANGE: Server now requires JWT_SECRET environment variable to be set Security fixes: - Remove hardcoded JWT secret fallback 'your-secret-key' from protectedImages.js - Add startup validation to ensure JWT_SECRET is properly configured - Reject insecure default values and short secrets - Server will refuse to start without proper JWT_SECRET This fixes a critical vulnerability where the application would use a publicly known secret if JWT_SECRET was not set, completely compromising authentication. Migration guide: docs/JWT_SECRET_MIGRATION.md 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
@@ -1,4 +1,9 @@
|
||||
require('dotenv').config();
|
||||
|
||||
// Validate critical environment variables before proceeding
|
||||
const { validateEnvironment } = require('./src/config/validateEnv');
|
||||
validateEnvironment();
|
||||
|
||||
const express = require('express');
|
||||
const helmet = require('helmet');
|
||||
const cors = require('cors');
|
||||
|
||||
Reference in New Issue
Block a user