This issue was moved to a discussion.
You can continue the conversation there. Go to discussion →
Question: Support for rotating keys/manually managing keys #1085
Labels
You can continue the conversation there. Go to discussion →
Rocket version: 0.4
Steps taken to answer question: Scanning the docs, reading up on stuff.
What documentation you believe should include an answer to this question: Either the state documentation or the cookies documentation.
Does Rocket offer any support for rotating keys used in Cookies/manually invalidating them through some form of IPC through a port on the local machine? I can just kill my rocket instance and swap the secret key, but I'd prefer something where I can rotate the keys while the server's still up and manage the migration of data encrypted with the old key to the new key.
I was thinking of implementing something like this, but was wondering if it was a good idea/why there's only one secret key/what that secret key is for (outside of cookie encryption).
The text was updated successfully, but these errors were encountered: