Files
bambuddy/backend/app/core
maziggy db68dda1f5 Document intentional JWT secret storage (CodeQL Alert #69)
Add explanatory comment for CodeQL alert about clear-text storage
of JWT secret. This is intentional and secure:
- JWT secrets must be readable by the application
- File permissions set to 0600 (owner read/write only)
- Standard practice for self-hosted apps (same as .env files)

The alert should be dismissed in GitHub Security tab as "Won't fix".
2026-02-02 08:19:51 +01:00
..
2025-11-28 10:23:59 +01:00
2026-02-02 08:16:33 +01:00