feat: standardize passwords at eight characters
This commit is contained in:
@@ -69,7 +69,7 @@ The built-in Actions job token can be disabled or lack registry scope on self-ho
|
||||
- `JWT_SECRET`: a unique random string of at least 32 characters.
|
||||
- `FRONTEND_ORIGIN`: the exact public application URL, for example `https://hub.example.com`.
|
||||
- `SUPERADMIN_EMAIL`: email address for the initial platform administrator.
|
||||
- `SUPERADMIN_PASSWORD`: password for that administrator (at least 12 characters).
|
||||
- `SUPERADMIN_PASSWORD`: password for that administrator (at least 8 characters).
|
||||
- `AUTH_RATE_LIMIT_MAX` and `AUTH_RATE_LIMIT_WINDOW_SECONDS` are optional login and public-auth throttling controls (defaults: 10 attempts per 900 seconds per source IP).
|
||||
- `JWT_SESSION_TTL`, `INVITATION_TTL_HOURS`, `PASSWORD_RESET_TTL_HOURS`, `BUNNY_EMBED_TOKEN_TTL_SECONDS`, and `AUDIT_LOG_PAGE_SIZE` tune operating policy without changing code.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user