Encrypt the notification channels' credentials at rest
The Gotify and ntfy tokens, the SMTP password and the webhook secret were stored as plain text in the settings table. They are now encrypted with the same key as integration credentials (CREDENTIALS_ENCRYPTION_KEY), marked with an "enc:v1:" prefix. Settings are decrypted when read and encrypted when written, so nothing else changes; values saved before this are converted at startup. An edit that doesn't touch a credential keeps its stored ciphertext, so a wrong or missing key (which reads as empty) can't be made permanent by an unrelated edit. Without a key new credentials fall back to plain storage, and the startup warning, .env.example and the Privacy page say so. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
1 parent
86dfa9ae2e
commit
f246410f24
5 files changed
+121
-9
No files matched your search
@@ -195,8 +195,11 @@ export default function Privacy() {
|
||||
<td>Until deleted.</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Integration and DNS credentials</td>
|
||||
<td>API tokens and passwords, encrypted (AES-256-GCM) with a key held in the server's environment, not in the database.</td>
|
||||
<td>Integration, DNS and notification credentials</td>
|
||||
<td>
|
||||
API tokens and passwords — including the Gotify/ntfy tokens, SMTP password and webhook secret — encrypted (AES-256-GCM) with a key held in
|
||||
the server's environment, not in the database. (If that key isn't set, notification credentials are kept unencrypted and the server says so at startup.)
|
||||
</td>
|
||||
<td>Until deleted. Settings → Backup exports include them, encrypted with a passphrase you choose.</td>
|
||||
</tr>
|
||||
<tr>
|
||||
|
||||
Reference in new issue
Block a user