mirror of
https://github.com/go-shiori/shiori.git
synced 2026-04-25 06:25:54 +03:00
[GH-ISSUE #782] SHIORI_HTTP_SECRET_KEY #374
Labels
No labels
component:backend
component:builds
component:builds
component:extension
component:frontend
component:readability
database
database:mysql
database:postgres
database:sqlite
feature:ebooks
github_actions
good first issue
hacktoberfest
note:duplicate?
note:fixed?
note:out-of-scope?
os:windows
priority:high
priority:low
pull-request
resolution:as-intended
resolution:cant-reproduce
resolution:duplicate
resolution:fixed
resolution:wontfix
tag:TBD
tag:big-task
tag:help-wanted
tag:huge-data
tag:meta
tag:more-info
tag:next
tag:no-stale
tag:requires-migrations
tag:research
tag:security 🛡️
tag:stale
tag:waiting-for-assignee
type:bug
type:documentation
type:enhancement
type:meta
type:ux
user:cli
user:web
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/shiori#374
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @LLKoder on GitHub (Nov 17, 2023).
Original GitHub issue: https://github.com/go-shiori/shiori/issues/782
Originally assigned to: @fmartingr on GitHub.
Data
Describe the bug / actual behavior
When I run Shiori in docker I get some WARN error:
SHIORI_HTTP_SECRET_KEY is not set, using random value. This means that all sessions will be invalidated on server restart.What do this error mean? How can I to fix it?
@fmartingr commented on GitHub (Nov 17, 2023):
Hey @LLKoder, you need to set the
SHIORI_HTTP_SECRET_KEYenvironment variable to something random to use as key for the session tokens. You can generate a pesudo-random string usingopenssl/pwgenor any number of tools online.@LLKoder commented on GitHub (Nov 17, 2023):
Hi, @fmartingr, do
shiorineed this key as unique every time when I start/restart service/system? Can you give a example please? I useshioriwith docker.Just I don't understand why this EVAR need users. If it don't use users why can
shiorinot generate it automatically?@fmartingr commented on GitHub (Nov 18, 2023):
Shiori generates one random every run, but for security purposes it must me set by the user. It is used to sign the sessions for the users (the authentication used to interact with the API).
How are you deploying shiori? docker compose/docker run? It something like this:
@LLKoder commented on GitHub (Nov 20, 2023):
@fmartingr, maybe don't need to close? This issue was remove from your tags either.
@fmartingr commented on GitHub (Nov 20, 2023):
Yeah leave it open for now so I use this as a reminder to properly update the docs 👍