Aias00 commented on PR #6408:
URL: https://github.com/apache/shenyu/pull/6408#issuecomment-5053145259

   The @PostConstruct init generates a SecureRandom secretKey per JVM when 
shenyu.jwt.secretKey is not explicitly configured. In a multi-instance Admin 
cluster this causes tokens signed by instance A to fail verification on 
instance B, resulting in random 401s for dashboard users. Consider either 
failing fast (throw new IllegalStateException) to force explicit configuration, 
or persisting the generated key somewhere shared across the cluster.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to