Skip to main content

SECRET_KEY_BASE_PREVIOUS

Constant SECRET_KEY_BASE_PREVIOUS 

Source
pub const SECRET_KEY_BASE_PREVIOUS: &str = "SECRET_KEY_BASE_PREVIOUS";
Expand description

Name of the Worker secret listing the previous SECRET_KEY_BASE values, during a rotation.

Comma-separated, newest first, each 64 characters or more. Session cookies encrypted with one of them are still read, then re-encrypted with the current SECRET_KEY_BASE on the same response; JWTs signed with one still verify until they expire. Rails’ cookies_rotations. Remove it once the longest session you care about has been re-encrypted (or after your JWT lifetime). Worker secrets cannot be read back: keep the value you replace, and upload it as SECRET_KEY_BASE_PREVIOUS with the new SECRET_KEY_BASE (ocre secrets push SECRET_KEY_BASE_PREVIOUS SECRET_KEY_BASE --file .prod.vars). Read once per request; no binding call.

§Examples

assert_eq!(ocre::SECRET_KEY_BASE_PREVIOUS, "SECRET_KEY_BASE_PREVIOUS");