Skip to content

Commit dd54320

Browse files
authored
fix: validate jwt secret is at least 16 characters (#3859)
1 parent befd3d4 commit dd54320

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

pkg/config/config.go

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -585,6 +585,9 @@ func (c *config) Load(path string, fsys fs.FS) error {
585585
return err
586586
}
587587
// Generate JWT tokens
588+
if len(c.Auth.JwtSecret.Value) < 16 {
589+
return errors.Errorf("Invalid config for auth.jwt_secret. Must be at least 16 characters")
590+
}
588591
if len(c.Auth.AnonKey.Value) == 0 {
589592
anonToken := CustomClaims{Role: "anon"}.NewToken()
590593
if signed, err := anonToken.SignedString([]byte(c.Auth.JwtSecret.Value)); err != nil {

0 commit comments

Comments
 (0)