forked from orbit-oss/flask
update docs about fallback order
This commit is contained in:
parent
fb54159861
commit
cbb6c36692
1 changed files with 6 additions and 3 deletions
|
|
@ -127,13 +127,16 @@ The following configuration values are used internally by Flask:
|
||||||
|
|
||||||
.. py:data:: SECRET_KEY_FALLBACKS
|
.. py:data:: SECRET_KEY_FALLBACKS
|
||||||
|
|
||||||
A list of old secret keys that can still be used for unsigning, most recent
|
A list of old secret keys that can still be used for unsigning. This allows
|
||||||
first. This allows a project to implement key rotation without invalidating
|
a project to implement key rotation without invalidating active sessions or
|
||||||
active sessions or other recently-signed secrets.
|
other recently-signed secrets.
|
||||||
|
|
||||||
Keys should be removed after an appropriate period of time, as checking each
|
Keys should be removed after an appropriate period of time, as checking each
|
||||||
additional key adds some overhead.
|
additional key adds some overhead.
|
||||||
|
|
||||||
|
Order should not matter, but the default implementation will test the last
|
||||||
|
key in the list first, so it might make sense to order oldest to newest.
|
||||||
|
|
||||||
Flask's built-in secure cookie session supports this. Extensions that use
|
Flask's built-in secure cookie session supports this. Extensions that use
|
||||||
:data:`SECRET_KEY` may not support this yet.
|
:data:`SECRET_KEY` may not support this yet.
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue