Security Settings
Encryption Settings
Session.configure do |config|
# Required: Secret key for encryption
config.secret = ENV["SESSION_SECRET"]
# Enforce secure secret (raises if using default)
config.require_secure_secret = true
# Digest algorithm for HMAC
config.digest_algorithm = :sha256
# Allow fallback to SHA1 for migration
config.digest_fallback = true
endKey Derivation (PBKDF2)
Redis Encryption
Client Binding
Security Properties
Property
Type
Default
Description
Last updated
Was this helpful?