Security: Don't allow default secret/token config parameters (#80)

This commit is contained in:
Eliot Partridge
2019-09-07 01:59:42 -05:00
committed by GitHub
parent b9d50c2665
commit cba4e94da2
3 changed files with 42 additions and 2 deletions
+10
View File
@@ -181,6 +181,16 @@ Add `config.json` file in root directory with following content. You can use `co
}
```
### NOTE!
You **MUST** provide **unique**, **random** values for the `secret` and `token` fields of your config. It is **extremely dangerous** to leave these as default, as these values serve as authentication tokens for internal APIs and session cookies.
To generate new values for these parameters, you can use the following command:
```bash
node -e "console.log(require('crypto').randomBytes(64).toString('base64'))"
```
## Running
### Your first build