security: remove all hardcoded API keys, require from environment
This commit is contained in:
@@ -2,9 +2,9 @@ APP_ENV=dev
|
||||
APP_HOST=127.0.0.1
|
||||
APP_PORT=8011
|
||||
DATABASE_URL=sqlite:///./coordinator.db
|
||||
CLIENT_API_KEYS=REDACTED_CLIENT_KEY,client_dev_key_2
|
||||
MINER_API_KEYS=REDACTED_MINER_KEY,miner_dev_key_2
|
||||
ADMIN_API_KEYS=REDACTED_ADMIN_KEY
|
||||
CLIENT_API_KEYS=${CLIENT_API_KEY},client_dev_key_2
|
||||
MINER_API_KEYS=${MINER_API_KEY},miner_dev_key_2
|
||||
ADMIN_API_KEYS=${ADMIN_API_KEY}
|
||||
HMAC_SECRET=change_me
|
||||
ALLOW_ORIGINS=*
|
||||
JOB_TTL_SECONDS=900
|
||||
|
||||
Reference in New Issue
Block a user