Repository navigation
Fix/auto generate jwt secret #94
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -8,9 +8,20 @@ | |
| * @see https://nextjs.org/docs/app/building-your-application/optimizing/instrumentation | ||
| */ | ||
|
|
||
| import crypto from "crypto"; | ||
|
|
||
| function ensureJwtSecret(): void { | ||
| if (!process.env.JWT_SECRET || process.env.JWT_SECRET.trim() === "") { | ||
| const generated = crypto.randomBytes(48).toString("base64"); | ||
| process.env.JWT_SECRET = generated; | ||
| console.log("[STARTUP] JWT_SECRET auto-generated (random 64-char secret)"); | ||
| } | ||
|
Comment on lines
+14
to
+18
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. The auto-generated secret is stored in |
||
| } | ||
|
|
||
| export async function register() { | ||
| // Only run on the server (not during build or in Edge runtime) | ||
| if (process.env.NEXT_RUNTIME === "nodejs") { | ||
| ensureJwtSecret(); | ||
| // Console log file capture (must be first — before any logging occurs) | ||
| const { initConsoleInterceptor } = await import("@/lib/consoleInterceptor"); | ||
| initConsoleInterceptor(); | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -6,12 +6,7 @@ import { isPublicRoute, verifyAuth, isAuthRequired } from "./shared/utils/apiAut | |
| import { checkBodySize, getBodySizeLimit } from "./shared/middleware/bodySizeGuard"; | ||
| import { isDraining } from "./lib/gracefulShutdown"; | ||
|
|
||
| // FASE-01: Fail-fast — no hardcoded fallback. Server must have JWT_SECRET configured. | ||
| if (!process.env.JWT_SECRET) { | ||
| console.error("[SECURITY] JWT_SECRET is not set. Authentication will fail."); | ||
| } | ||
|
|
||
| const SECRET = new TextEncoder().encode(process.env.JWT_SECRET); | ||
| const SECRET = new TextEncoder().encode(process.env.JWT_SECRET || ""); | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. The use of an empty string ( |
||
|
|
||
| export async function proxy(request) { | ||
| const { pathname } = request.nextUrl; | ||
|
|
||
Uh oh!
There was an error while loading. Please reload this page.