Copilot commented on code in PR #7063:
URL: https://github.com/apache/shenyu/pull/7063#discussion_r4011476499


##########
shenyu-dist/shenyu-docker-compose-dist/src/main/resources/docker-compose.yaml:
##########
@@ -44,9 +44,12 @@ services:
     ports:
       - "9095:9095"
     environment:
-      # Required: replace with your own secure key in production.
+      # Required: generate your own secure key and export it, e.g.
+      #   openssl rand -base64 48
+      #   export SHENYU_JWT_SECRETKEY=<the-generated-value>
+      # docker compose refuses to start until SHENYU_JWT_SECRETKEY is set.
       # In a multi-instance Admin cluster, all instances must share the same 
secretKey.
-      - SHENYU_JWT_SECRETKEY=please-replace-with-your-own-secret-key
+      - SHENYU_JWT_SECRETKEY=${SHENYU_JWT_SECRETKEY:?SHENYU_JWT_SECRETKEY must 
be set. Generate one with 'openssl rand -base64 48' and export it.}

Review Comment:
   This required Compose interpolation makes the documented `install.sh` path 
invalid: `install.sh` tells users they may set `shenyu.jwt.secretKey` only in 
`shenyu-admin/conf/application.yml` (lines 84-86), but Compose aborts before 
the container starts whenever `SHENYU_JWT_SECRETKEY` is not exported. Update 
the installer/documentation to require the environment variable, or make this 
interpolation optional and rely on the mounted configuration file.



##########
shenyu-admin/src/main/java/org/apache/shenyu/admin/config/properties/JwtProperties.java:
##########
@@ -40,7 +40,8 @@ public class JwtProperties {
 
     @PostConstruct
     private void init() {
-        if (StringUtils.isBlank(secretKey) || 
AdminConstants.JWT_DEFAULT_SECRET_KEY.equals(this.secretKey)) {
+        if (StringUtils.isBlank(secretKey) || 
AdminConstants.JWT_DEFAULT_SECRET_KEY.equals(this.secretKey)
+                || 
AdminConstants.JWT_PUBLIC_SECRET_KEY.equals(this.secretKey)) {

Review Comment:
   The new branch rejects a non-blank, explicitly configured key, but the 
exception still says `shenyu.jwt.secretKey is not configured`. An operator 
migrating from the old Compose file will see a misleading diagnosis; please 
make this message explain that blank, default, and publicly known keys are all 
rejected (or provide a distinct message for this sentinel).



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to