From 8691920ba5929745def1c6594e0633cebe661d26 Mon Sep 17 00:00:00 2001 From: Waldir Montoya Date: Thu, 3 Aug 2023 12:37:55 -0500 Subject: [PATCH] Describe what is a session secret Signed-off-by: Waldir Montoya --- docs/auth/auth0/provider.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/auth/auth0/provider.md b/docs/auth/auth0/provider.md index e9393cfa0b..dabc5fa3c1 100644 --- a/docs/auth/auth0/provider.md +++ b/docs/auth/auth0/provider.md @@ -47,6 +47,7 @@ The Auth0 provider is a structure with three configuration keys: - `clientSecret`: The Application client secret, found on the Auth0 Application page - `domain`: The Application domain, found on the Auth0 Application page +- `sessionsecret`: The session secret is a key used for signing and/or encrypting cookies set by the application to maintain session state. In this case, 'your session secret' should be replaced with a long, complex, and unique string that only your application knows. Because Auth0 requires a session you need to give the session a secret key.