Skip to content

Commit

Permalink
docs: add note on length of secret
Browse files Browse the repository at this point in the history
closes #919
  • Loading branch information
lukaselmer authored and dougwilson committed Jan 28, 2024
1 parent 2a7a50b commit e5f19ce
Showing 1 changed file with 3 additions and 0 deletions.
3 changes: 3 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -295,6 +295,9 @@ the secret without invalidating sessions, provide an array of secrets, with the
secret as first element of the array, and including previous secrets as the later
elements.

**Note** HMAC-256 is used to sign the session ID. For this reason, the secret should
contain at least 32 bytes of entropy.

##### store

The session store instance, defaults to a new `MemoryStore` instance.
Expand Down

0 comments on commit e5f19ce

Please sign in to comment.