diff --git a/internal/config/config.go b/internal/config/config.go index cb5b9b9..702f1b8 100644 --- a/internal/config/config.go +++ b/internal/config/config.go @@ -262,15 +262,16 @@ func (c *Config) ensureStateDirWritable() error { // validate checks that all required configuration values are set and // that every value is within its valid range. func (c *Config) validate() error { + // The signing key value is never echoed in error messages. if c.SigningKey == "" { - return fmt.Errorf("signing_key is required") + return fmt.Errorf("config key %q: a value is required", "signing_key") } // Minimum key length for security (32 bytes = 256 bits) const minKeyLength = 32 if len(c.SigningKey) < minKeyLength { - return fmt.Errorf("signing_key must be at least %d characters, got %d", - minKeyLength, len(c.SigningKey)) + return fmt.Errorf("config key %q: value must be at least %d characters, got %d", + "signing_key", minKeyLength, len(c.SigningKey)) } const maxPort = 65535