From 0d809f6129b866d57b2b6bbe84ea5ea4770a2acd Mon Sep 17 00:00:00 2001 From: Teng Siong Ong Date: Tue, 21 Aug 2012 20:37:58 -0700 Subject: remind user a good way to generate a secret code. --- .../rails/app/templates/config/initializers/secret_token.rb.tt | 3 +++ 1 file changed, 3 insertions(+) (limited to 'railties/lib/rails/generators') diff --git a/railties/lib/rails/generators/rails/app/templates/config/initializers/secret_token.rb.tt b/railties/lib/rails/generators/rails/app/templates/config/initializers/secret_token.rb.tt index e02397aaf9..21a5de4cba 100644 --- a/railties/lib/rails/generators/rails/app/templates/config/initializers/secret_token.rb.tt +++ b/railties/lib/rails/generators/rails/app/templates/config/initializers/secret_token.rb.tt @@ -2,8 +2,11 @@ # Your secret key for verifying the integrity of signed cookies. # If you change this key, all old signed cookies will become invalid! + # Make sure the secret is at least 30 characters and all random, # no regular words or you'll be exposed to dictionary attacks. +# You can generate a safe secret key with the command `rake secret`. + # Make sure your secret_token is kept private # if you're sharing your code publicly. <%= app_const %>.config.secret_token = '<%= app_secret %>' -- cgit v1.2.3