fix: resolve security review findings on .env.example template (E00-S04-T05)
CI / Frozen lockfile install (pull_request) Successful in 53s
CI / Secrets not embedded (E00-S02-T08) (pull_request) Successful in 25s
CI / Database-postgres import isolation (E00-S03-T02) (pull_request) Successful in 24s
CI / Migration ledger (E00-S03-T03) (pull_request) Successful in 52s
CI / Migration advisory lock (E00-S03-T04) (pull_request) Successful in 49s
CI / Migration failure diagnostic (E00-S03-T05) (pull_request) Successful in 47s
CI / App readiness after migrations (E00-S03-T06) (pull_request) Successful in 1m8s
CI / Field-specific startup errors (E00-S04-T02) (pull_request) Successful in 1m2s
CI / Secret redaction from logs (E00-S04-T03) (pull_request) Successful in 1m5s
CI / Env adapter owns process.env (E00-S04-T04) (pull_request) Successful in 1m2s
CI / TypeBox/Ajv config schema (E00-S04-T01) (pull_request) Successful in 58s
CI / .env.example placeholders only (E00-S04-T05) (pull_request) Successful in 24s
CI / Compose config (E00-S03-T01) (pull_request) Successful in 25s
CI / Frozen lockfile install (pull_request) Successful in 53s
CI / Secrets not embedded (E00-S02-T08) (pull_request) Successful in 25s
CI / Database-postgres import isolation (E00-S03-T02) (pull_request) Successful in 24s
CI / Migration ledger (E00-S03-T03) (pull_request) Successful in 52s
CI / Migration advisory lock (E00-S03-T04) (pull_request) Successful in 49s
CI / Migration failure diagnostic (E00-S03-T05) (pull_request) Successful in 47s
CI / App readiness after migrations (E00-S03-T06) (pull_request) Successful in 1m8s
CI / Field-specific startup errors (E00-S04-T02) (pull_request) Successful in 1m2s
CI / Secret redaction from logs (E00-S04-T03) (pull_request) Successful in 1m5s
CI / Env adapter owns process.env (E00-S04-T04) (pull_request) Successful in 1m2s
CI / TypeBox/Ajv config schema (E00-S04-T01) (pull_request) Successful in 58s
CI / .env.example placeholders only (E00-S04-T05) (pull_request) Successful in 24s
CI / Compose config (E00-S03-T01) (pull_request) Successful in 25s
Addresses PR #404 review findings F2/F3/F4 on issue #186: - F3 (fail-closed): ship EPPP_SESSION_SECRET placeholder as `change-me` (9 chars), shorter than the schema's 32-character minimum, so an unedited `cp .env.example .env` is rejected at startup instead of booting with a publicly known secret. - F2 (gitleaks-clean): build the secret-shaped mutation-probe literal at runtime from short non-secret fragments; the branch no longer embeds a secret-shaped literal in the test source. - F4 (masked messages): assertion messages mask/truncate values that come from the template instead of echoing the raw string. - test: add a fail-closed length test for the EPPP_SESSION_SECRET placeholder (< 32 chars); keep mutation probes non-vacuous.
This commit is contained in:
+5
-2
@@ -28,8 +28,11 @@ DATABASE_URL=postgres://localhost:5432/eppp
|
||||
|
||||
# Admin-session secret — REQUIRED and at least 32 characters (the config
|
||||
# schema's required field; Security-and-Operations §32/§26). Generate a fresh
|
||||
# one with `openssl rand -hex 32` and replace the placeholder below.
|
||||
EPPP_SESSION_SECRET=change-me-to-a-random-32-character-secret
|
||||
# one with `openssl rand -hex 32` and replace the placeholder below. The
|
||||
# placeholder is intentionally SHORTER than the 32-character minimum, so an
|
||||
# unedited `cp .env.example .env` is rejected at startup (fails closed)
|
||||
# instead of booting with a publicly known secret.
|
||||
EPPP_SESSION_SECRET=change-me
|
||||
|
||||
# --- Docker Compose overrides (optional — compose.yaml has dev defaults) ------
|
||||
|
||||
|
||||
Reference in New Issue
Block a user