mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-10-01 03:31:25 +02:00
Add explanatory comment for CodeQL alert about clear-text storage of JWT secret. This is intentional and secure: - JWT secrets must be readable by the application - File permissions set to 0600 (owner read/write only) - Standard practice for self-hosted apps (same as .env files) The alert should be dismissed in GitHub Security tab as "Won't fix".