Skip to content

Commit 637a5e3

Browse files
committed
deprecate secret key for paseto private
1 parent 28d8110 commit 637a5e3

7 files changed

Lines changed: 25 additions & 14 deletions

File tree

.github/workflows/go.yml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,6 @@ jobs:
3434
echo "PASETO_PRIVATE_KEY=UayDa4OMDpm3CvIT+iSC39iDyPlsui0pNQYDEZ1pbo1LsIrO4p/aVuCBWz6LiYvzj9pc+gn0gLwRd0CoHV+nxw==" >> .env.test
3535
echo "PASETO_PUBLIC_KEY=S7CKzuKf2lbggVs+i4mL84/aXPoJ9IC8EXdAqB1fp8c=" >> .env.test
3636
echo "ROOT_EMAIL=admin@example.com" >> .env.test
37-
echo "SECRET_KEY=test-key" >> .env.test
3837
3938
# Run unit tests (exclude integration tests)
4039
go test -race -coverprofile=coverage-unit.txt -covermode=atomic $(go list ./... | grep -v '/tests/integration') -v
@@ -126,7 +125,6 @@ jobs:
126125
echo "PASETO_PRIVATE_KEY=UayDa4OMDpm3CvIT+iSC39iDyPlsui0pNQYDEZ1pbo1LsIrO4p/aVuCBWz6LiYvzj9pc+gn0gLwRd0CoHV+nxw==" >> .env.test
127126
echo "PASETO_PUBLIC_KEY=S7CKzuKf2lbggVs+i4mL84/aXPoJ9IC8EXdAqB1fp8c=" >> .env.test
128127
echo "ROOT_EMAIL=admin@example.com" >> .env.test
129-
echo "SECRET_KEY=test-key" >> .env.test
130128
echo "DB_HOST=localhost" >> .env.test
131129
echo "DB_PORT=5433" >> .env.test
132130
echo "DB_USER=notifuse_test" >> .env.test

Makefile

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -50,7 +50,6 @@ docker-run:
5050
-p 8080:8080 \
5151
-e PASETO_PRIVATE_KEY=$${PASETO_PRIVATE_KEY} \
5252
-e PASETO_PUBLIC_KEY=$${PASETO_PUBLIC_KEY} \
53-
-e SECRET_KEY=$${SECRET_KEY} \
5453
-e ROOT_EMAIL=$${ROOT_EMAIL:-admin@example.com} \
5554
-e API_ENDPOINT=$${API_ENDPOINT:-http://localhost:8080} \
5655
-e WEBHOOK_ENDPOINT=$${WEBHOOK_ENDPOINT:-http://localhost:8080} \

README.md

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -98,7 +98,15 @@ Notifuse follows clean architecture principles with clear separation of concerns
9898
```
9999

100100
3. **Generate PASETO keys**:
101-
Visit [paseto.notifuse.com](https://paseto.notifuse.com) to generate your PASETO keys
101+
Visit [paseto.notifuse.com](https://paseto.notifuse.com) to generate your PASETO keys, or use the built-in keygen command:
102+
103+
```bash
104+
# Generate keys manually
105+
make keygen
106+
107+
# Or directly with Go
108+
go run cmd/keygen/main.go
109+
```
102110

103111
4. **Start the services**:
104112

@@ -127,7 +135,7 @@ The docker-compose includes a PostgreSQL container for quick testing. Simply run
127135

128136
Copy `env.example` to `.env` and configure:
129137

130-
- **Required**: `ROOT_EMAIL`, `API_ENDPOINT`, `PASETO_PRIVATE_KEY`, `PASETO_PUBLIC_KEY`, `SECRET_KEY`
138+
- **Required**: `ROOT_EMAIL`, `API_ENDPOINT`, `PASETO_PRIVATE_KEY`, `PASETO_PUBLIC_KEY`
131139
- **Database**: Configure `DB_HOST`, `DB_USER`, `DB_PASSWORD` for your external PostgreSQL
132140
- **SMTP Settings**: Configure your email provider for system emails
133141
- **SSL**: Set `DB_SSLMODE=require` for secure database connections

TODO.md

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,13 @@
11
# TODO
22

3-
- docs: newsletter input form example
3+
- store last cron timestamp in DB and render an alert if it's not running (only in production)
4+
- better design for system email
5+
- double opt in template for newsletter
6+
- welcome template for notifuse newsletter
7+
- page vs loops.so
8+
- page vs listmonk
9+
- page vs mailerlite
10+
- page vs mautic
411

512
## Eventual features
613

config/config.go

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ import (
1010
"github.com/spf13/viper"
1111
)
1212

13-
const VERSION = "3.2"
13+
const VERSION = "3.3"
1414

1515
type Config struct {
1616
Server ServerConfig
@@ -242,8 +242,11 @@ func LoadWithOptions(opts LoadOptions) (*Config, error) {
242242
return nil, fmt.Errorf("error creating PASETO public key: %w", err)
243243
}
244244

245-
if v.GetString("SECRET_KEY") == "" {
246-
return nil, fmt.Errorf("SECRET_KEY is required")
245+
// Use PASETO private key as secret key if SECRET_KEY is not provided
246+
secretKey := v.GetString("SECRET_KEY")
247+
if secretKey == "" {
248+
// Use base64 encoded PASETO private key as the secret key
249+
secretKey = privateKeyBase64
247250
}
248251

249252
config := &Config{
@@ -278,7 +281,7 @@ func LoadWithOptions(opts LoadOptions) (*Config, error) {
278281
PasetoPublicKey: publicKey,
279282
PasetoPrivateKeyBytes: privateKeyBytes,
280283
PasetoPublicKeyBytes: publicKeyBytes,
281-
SecretKey: v.GetString("SECRET_KEY"),
284+
SecretKey: secretKey,
282285
},
283286
Demo: DemoConfig{
284287
FileManagerEndpoint: v.GetString("DEMO_FILE_MANAGER_ENDPOINT"),

docker-compose.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,6 @@ services:
2020
- ENVIRONMENT=production
2121
- PASETO_PRIVATE_KEY=${PASETO_PRIVATE_KEY:-d04zCk3Fa45oOjDWHpAvc1AZxnLdGffOnNWK+Jt2yXf37+FTfuMMHb8flcfPMqLluRR3rvhbr555r6j1DEigrA==}
2222
- PASETO_PUBLIC_KEY=${PASETO_PUBLIC_KEY:-9+/hU37jDB2/H5XHzzKi5bkUd674W6+eea+o9QxIoKw=}
23-
- SECRET_KEY=${SECRET_KEY:-change_me_32_character_secret_key}
2423
- ROOT_EMAIL=${ROOT_EMAIL:-admin@example.com}
2524
- SMTP_HOST=${SMTP_HOST:-smtp.example.com}
2625
- SMTP_PORT=${SMTP_PORT:-587}

env.example

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -21,9 +21,6 @@ API_ENDPOINT=https://emails.yourcompany.com
2121
PASETO_PRIVATE_KEY=your_base64_encoded_private_key_here
2222
PASETO_PUBLIC_KEY=your_base64_encoded_public_key_here
2323

24-
# Secret key for database encryption (32 characters minimum)
25-
SECRET_KEY=your_32_character_secret_key_here_123
26-
2724
# SMTP Configuration for system emails (password resets, invitations, etc.)
2825
SMTP_HOST=smtp.gmail.com
2926
SMTP_PORT=587

0 commit comments

Comments
 (0)