Kratos cookie secret length requirement unclear
@unatasha8 ya está trabajando en esto.
Desde el 20/11/2025.
Evaluación
Este issue todavía no se ha evaluado.
Descripción
Preflight checklist
- I could not find a solution in the existing issues, docs, nor discussions.
- I agree to follow this project's Code of Conduct.
- I have read and am following this repository's Contribution Guidelines.
- I have joined the Ory Community Slack.
- I am signed up to the Ory Security Patch Newsletter.
Ory Network Project
No response
Describe the bug
From the docs:
So let's play the password game!
Assuming 1 character = 1 byte, this suggest yaml-escaping 32 raw bytes. More than 256 bit entropy would be impossible, unless unicode characters are allowed, but I've never seen emojiis in (cookie) secrets.
To make it more sane, I'd expect kratos to hash the passed value before usage, regardless of the length of the value to extract full entropy, and exactly that seems to be done: https://github.com/ory/kratos/blob/50f1b8f0df8636cea94d1100c1dc68dd8f6bdfc5/driver/registry_default.go#L530-L534
IMHO, the documentation should be updated to remove the secret length requirement.
Reproducing the bug
Open https://www.ory.com/docs/kratos/guides/select-cipher-algorithm#xchacha20-poly1305 and https://www.ory.com/docs/kratos/guides/secret-key-rotation and follow the guide rigorously.
Relevant log output
The bug is in the documentation.
Relevant configuration
The bug is in the documentation.
Version
The bug is in the documentation.
On which operating system are you observing this issue?
None
In which environment are you deploying?
None
Additional Context
No response
- Lenguaje dominante
- TypeScript
- Estrellas
- 161
- Forks
- 1.9k
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de ory/docs
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
-
good first issue help wanted upstream
Dificultad 1/5 1-3 horas Aptitud para principiantes 72/100
-
bug
Dificultad 1/5 Menos de una hora Aptitud para principiantes 78/100
-
good first issue help wanted upstream
Dificultad 1/5 1-3 horas Aptitud para principiantes 72/100
-
Shared kratos pages can only belong to one sidebar — OEL readers lose navigation contextQuizá libre de nuevo @hperl la tomó hace 78 días y no hay ningún pull request abierto. Abierto
Issues similares
-
triage
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
mermaid-js/mermaid-live-editor#2053 ·
Los mantenedores suelen responder en 1 día
-
factory
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
jessepollak/home#1455 ·
Los mantenedores suelen responder en 1 día
-
community first-timers-only good first issue hacktoberfest help wanted low hanging fruit up-for-grabs
Dificultad 1/5 Menos de una hora Aptitud para principiantes 95/100
lingdojo/kana-dojo#31227 · 1 comentario · 5 reacciones ·
Los mantenedores suelen responder en 1 día
-
mobile: device viewer shows dark status bar icons on its dark backdrop in light mode (Android)Abierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 92/100
appandflow/stim#1838 ·
Los mantenedores suelen responder en 1 día