94dd3fcff460890317e0e0c5aafa6725e64bed0c
Security review flagged a hardcoded JWT secret fallback. A booth machine started without JWT_SECRET would have signed tokens with a publicly-known default, letting anyone forge an admin token — defeating the local-auth anti-fraud model. - requireJwtSecret() refuses to start on a missing, <32-char, or placeholder secret (no insecure default). - Add sign.expiresIn: 8h so minted tokens expire (bound to a shift). - Add apps/server/.env.example documenting JWT_SECRET + how to generate it. Verified: refuses with no secret and with the old placeholder; boots and serves /health with a valid `openssl rand -hex 32` secret.
Description
No description provided