fix-backend-review-findings (ornith-35): oauth empty-token guard, session-secret startup assertion, OAuth email-link test
Fixes from ornith's backend code review, implemented by ornith-35 (cross-review by qwopus35b pending). 129/129 tests green.
This commit is contained in:
@@ -7,6 +7,12 @@ import type { CacheRepository } from '../cache/CacheRepository.ts';
|
||||
|
||||
export const SESSION_COOKIE = 'iflow_session';
|
||||
export const OAUTH_STATE_COOKIE = 'iflow_oauth_state';
|
||||
// Fail-fast: refuse to run with the unsafe default secret outside dev.
|
||||
const isDev = process.env.NODE_ENV === 'development' || process.env.NODE_ENV === undefined;
|
||||
if (!process.env.IFLOW_SESSION_SECRET && !isDev) {
|
||||
throw new Error('IFLOW_SESSION_SECRET is not set and NODE_ENV is not "development". The default dev secret must never be used in production.');
|
||||
}
|
||||
|
||||
const SESSION_SECRET = process.env.IFLOW_SESSION_SECRET ?? 'dev-secret-change-me';
|
||||
const SESSION_TTL_MS = 30 * 24 * 60 * 60 * 1000; // 30 days
|
||||
|
||||
|
||||
Reference in New Issue
Block a user