Copilot commented on code in PR #7063:
URL: https://github.com/apache/shenyu/pull/7063#discussion_r4011476499
##########
shenyu-dist/shenyu-docker-compose-dist/src/main/resources/docker-compose.yaml:
##########
@@ -44,9 +44,12 @@ services:
ports:
- "9095:9095"
environment:
- # Required: replace with your own secure key in production.
+ # Required: generate your own secure key and export it, e.g.
+ # openssl rand -base64 48
+ # export SHENYU_JWT_SECRETKEY=<the-generated-value>
+ # docker compose refuses to start until SHENYU_JWT_SECRETKEY is set.
# In a multi-instance Admin cluster, all instances must share the same
secretKey.
- - SHENYU_JWT_SECRETKEY=please-replace-with-your-own-secret-key
+ - SHENYU_JWT_SECRETKEY=${SHENYU_JWT_SECRETKEY:?SHENYU_JWT_SECRETKEY must
be set. Generate one with 'openssl rand -base64 48' and export it.}
Review Comment:
This required Compose interpolation makes the documented `install.sh` path
invalid: `install.sh` tells users they may set `shenyu.jwt.secretKey` only in
`shenyu-admin/conf/application.yml` (lines 84-86), but Compose aborts before
the container starts whenever `SHENYU_JWT_SECRETKEY` is not exported. Update
the installer/documentation to require the environment variable, or make this
interpolation optional and rely on the mounted configuration file.
##########
shenyu-admin/src/main/java/org/apache/shenyu/admin/config/properties/JwtProperties.java:
##########
@@ -40,7 +40,8 @@ public class JwtProperties {
@PostConstruct
private void init() {
- if (StringUtils.isBlank(secretKey) ||
AdminConstants.JWT_DEFAULT_SECRET_KEY.equals(this.secretKey)) {
+ if (StringUtils.isBlank(secretKey) ||
AdminConstants.JWT_DEFAULT_SECRET_KEY.equals(this.secretKey)
+ ||
AdminConstants.JWT_PUBLIC_SECRET_KEY.equals(this.secretKey)) {
Review Comment:
The new branch rejects a non-blank, explicitly configured key, but the
exception still says `shenyu.jwt.secretKey is not configured`. An operator
migrating from the old Compose file will see a misleading diagnosis; please
make this message explain that blank, default, and publicly known keys are all
rejected (or provide a distinct message for this sentinel).
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]