chore: fix InsecureKeyLengthWarning

Fixing the InsecureKeyLengthWarning by increasing the generated
key length from 12 to 24 which increases the base64 value from
16 to 32 chars
This commit is contained in:
guenhter 2026-06-10 13:33:08 +02:00
parent b1d40f3409
commit f9524dfd1c
2 changed files with 2 additions and 2 deletions

View file

@ -38,7 +38,7 @@ def serve(
typer.echo('Loading WEBUI_SECRET_KEY from file, not provided as an environment variable.')
if not KEY_FILE.exists():
typer.echo(f'Generating a new secret key and saving it to {KEY_FILE}')
KEY_FILE.write_bytes(base64.b64encode(random.randbytes(12)))
KEY_FILE.write_bytes(base64.b64encode(random.randbytes(24)))
typer.echo(f'Loading WEBUI_SECRET_KEY from {KEY_FILE}')
os.environ['WEBUI_SECRET_KEY'] = KEY_FILE.read_text()

View file

@ -38,7 +38,7 @@ if [[ -z "${WEBUI_SECRET_KEY:-}" && -z "${WEBUI_JWT_SECRET_KEY:-}" ]]; then
if [[ ! -f "$KEY_FILE" ]]; then
echo "Generating new WEBUI_SECRET_KEY..."
head -c 12 /dev/random | base64 > "$KEY_FILE"
head -c 24 /dev/random | base64 > "$KEY_FILE"
fi
echo "Loading WEBUI_SECRET_KEY from ${KEY_FILE}"