mirror of
https://github.com/infiniflow/ragflow.git
synced 2025-12-08 20:42:30 +08:00
Update logging for auto-generated SECRET_KEY (#11458)
Remove the code that exposes the generated key in the log, as it poses a security risk. <img width="1170" height="269" alt="image" src="https://github.com/user-attachments/assets/03c42516-af1a-49a4-ade2-4ef3ee4b3cdd" /> --------- Co-authored-by: Kevin Hu <kevinhu.sh@gmail.com>
This commit is contained in:
@ -139,7 +139,7 @@ def _get_or_create_secret_key():
|
|||||||
import logging
|
import logging
|
||||||
|
|
||||||
new_key = secrets.token_hex(32)
|
new_key = secrets.token_hex(32)
|
||||||
logging.warning(f"SECURITY WARNING: Using auto-generated SECRET_KEY. Generated key: {new_key}")
|
logging.warning("SECURITY WARNING: Using auto-generated SECRET_KEY.")
|
||||||
return new_key
|
return new_key
|
||||||
|
|
||||||
class StorageFactory:
|
class StorageFactory:
|
||||||
|
|||||||
Reference in New Issue
Block a user