Merge pull request #18261 from Classic298/patch-1

enh: lower JWT expiration default value and add warn message
This commit is contained in:
Tim Jaeryang Baek 2025-10-14 18:35:03 -05:00 committed by GitHub
commit 94806555bf
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -307,9 +307,15 @@ API_KEY_ALLOWED_ENDPOINTS = PersistentConfig(
JWT_EXPIRES_IN = PersistentConfig(
"JWT_EXPIRES_IN", "auth.jwt_expiry", os.environ.get("JWT_EXPIRES_IN", "-1")
"JWT_EXPIRES_IN", "auth.jwt_expiry", os.environ.get("JWT_EXPIRES_IN", "4w")
)
if JWT_EXPIRES_IN.value == "-1":
log.warning(
"⚠️ SECURITY WARNING: JWT_EXPIRES_IN is set to '-1'\n"
" See: https://docs.openwebui.com/getting-started/env-configuration\n"
)
####################################
# OAuth config
####################################