fix: redact secret diagnostics
This commit is contained in:
@@ -69,13 +69,13 @@ Quality bar:
|
||||
Objective: make self-hosted deployments safer.
|
||||
|
||||
Priority tasks:
|
||||
- Keep raw secrets out of diagnostics, logs, and UI responses.
|
||||
- Add startup validation for production settings.
|
||||
- Add backup and restore documentation.
|
||||
- Add a release checklist covering migrations, tests, and smoke checks.
|
||||
|
||||
Delivered:
|
||||
- Documented a 1Password secret-injection deployment flow for local, Docker Compose, and systemd deployments.
|
||||
- Redacted secret-like values from mail-source diagnostics, stored import history, OAuth error logs, and validated admin auth contexts.
|
||||
|
||||
## Later Milestones
|
||||
|
||||
|
||||
+2
-1
@@ -96,9 +96,10 @@ Goal: make production deployments safer and easier to operate.
|
||||
|
||||
Delivered:
|
||||
- 1Password-based secret injection flow for local, Docker Compose, and systemd deployments.
|
||||
- Raw mailbox/OAuth secrets are redacted from mail-source diagnostics, import history, and OAuth error logs.
|
||||
- Admin authentication contexts no longer carry raw API keys after validation.
|
||||
|
||||
Planned:
|
||||
- Avoid exposing raw mailbox/OAuth secrets in logs, UI responses, and diagnostics.
|
||||
- Add startup checks for production-critical configuration.
|
||||
- Add backup/restore guidance for database deployments.
|
||||
- Add release checklist covering migrations, tests, and smoke checks.
|
||||
|
||||
@@ -156,6 +156,7 @@ This file tracks the specific implementation tasks for each milestone of the DMA
|
||||
|
||||
## Future Milestones
|
||||
- [x] Production secret handling guide using 1Password injection
|
||||
- [x] Redact mailbox/OAuth secrets from diagnostics, logs, import history, and auth contexts
|
||||
- [ ] Apprise notifications and alert rules
|
||||
- [ ] DNS health guidance and Cloudflare read-only inspection
|
||||
- [ ] Guided setup and operator health pages
|
||||
|
||||
Reference in New Issue
Block a user