Chore: enforce min length for HOMEPAGE_AUTH_SECRET

This commit is contained in:
shamoon
2026-08-07 09:28:06 -07:00
parent 9dd0cdb8da
commit 31e93252c8
4 changed files with 50 additions and 14 deletions
+8
View File
@@ -6,6 +6,8 @@ import CredentialsProvider from "next-auth/providers/credentials";
import { isAuthEnabled } from "utils/env";
import createLogger from "utils/logger";
const MIN_AUTH_SECRET_LENGTH = 32;
const authEnabled = isAuthEnabled();
const issuer = process.env.HOMEPAGE_OIDC_ISSUER;
const clientId = process.env.HOMEPAGE_OIDC_CLIENT_ID;
@@ -63,6 +65,12 @@ if (authEnabled) {
} else if (!homepageAuthPassword || !process.env.NEXTAUTH_SECRET) {
throw new Error("Password auth is enabled but required settings are missing.");
}
if (process.env.NEXTAUTH_SECRET.length < MIN_AUTH_SECRET_LENGTH) {
throw new Error(
`HOMEPAGE_AUTH_SECRET (or NEXTAUTH_SECRET) must be at least ${MIN_AUTH_SECRET_LENGTH} characters. Generate one with: openssl rand -base64 32`,
);
}
}
// Give fail2ban / CrowdSec etc something to match on
+3 -3
View File
@@ -105,7 +105,7 @@ describe("pages/api/mcp", () => {
process.env.HOMEPAGE_MCP_ENABLED = "true";
process.env.HOMEPAGE_AUTH_ENABLED = "true";
process.env.HOMEPAGE_AUTH_PASSWORD = "password";
process.env.HOMEPAGE_AUTH_SECRET = "auth-secret";
process.env.HOMEPAGE_AUTH_SECRET = "rk3Xk9wQ0mVJt7cZbN2yLpA8sHdF4gRuEwTiOaSvBnM=";
process.env.HOMEPAGE_EXTERNAL_URL = "https://homepage.example";
getServerSession.mockResolvedValueOnce({ user: { name: "Homepage" } });
const handler = await loadHandler();
@@ -122,7 +122,7 @@ describe("pages/api/mcp", () => {
process.env.HOMEPAGE_MCP_ENABLED = "true";
process.env.HOMEPAGE_AUTH_ENABLED = "true";
process.env.HOMEPAGE_AUTH_PASSWORD = "password";
process.env.HOMEPAGE_AUTH_SECRET = "auth-secret";
process.env.HOMEPAGE_AUTH_SECRET = "rk3Xk9wQ0mVJt7cZbN2yLpA8sHdF4gRuEwTiOaSvBnM=";
process.env.HOMEPAGE_EXTERNAL_URL = "https://homepage.example";
getServerSession.mockResolvedValueOnce(null);
const handler = await loadHandler();
@@ -138,7 +138,7 @@ describe("pages/api/mcp", () => {
process.env.HOMEPAGE_MCP_ENABLED = "true";
process.env.HOMEPAGE_AUTH_ENABLED = "true";
process.env.HOMEPAGE_AUTH_PASSWORD = "password";
process.env.HOMEPAGE_AUTH_SECRET = "auth-secret";
process.env.HOMEPAGE_AUTH_SECRET = "rk3Xk9wQ0mVJt7cZbN2yLpA8sHdF4gRuEwTiOaSvBnM=";
process.env.HOMEPAGE_EXTERNAL_URL = "https://homepage.example";
process.env.HOMEPAGE_MCP_TOKEN = "secret";
const handler = await loadHandler();