auth: salt and token key should not have default values #280

Closed
fsouza opened this Issue Jan 18, 2013 · 0 comments

Projects

None yet

1 participant

@fsouza

Marking as a bug, because it's a security issue. Very easy to fix, but still a security issue.

@fsouza fsouza added a commit that referenced this issue Jan 22, 2013
@fsouza fsouza auth: remove default value for salt and token key
Related to #280. I will close the issue after I fix the loadConfig
dependency and update the docs.
7f377cb
@fsouza fsouza added a commit that referenced this issue Jan 22, 2013
@fsouza fsouza auth: call loadConfig in proper places
Calling it in init won't always work. This tsuru.conf file may load
after the init is called, and it would panic.

Related to #280.
69138e7
@fsouza fsouza closed this in 6dd45e1 Jan 22, 2013
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment