Aias00 commented on PR #6408: URL: https://github.com/apache/shenyu/pull/6408#issuecomment-5053145259
The @PostConstruct init generates a SecureRandom secretKey per JVM when shenyu.jwt.secretKey is not explicitly configured. In a multi-instance Admin cluster this causes tokens signed by instance A to fail verification on instance B, resulting in random 401s for dashboard users. Consider either failing fast (throw new IllegalStateException) to force explicit configuration, or persisting the generated key somewhere shared across the cluster. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
