mirror of
https://github.com/Routstr/routstr-core.git
synced 2026-08-09 02:54:37 +00:00
upstream_api_key was added to SECRET_FIELDS, so it was stripped from every blob write — but unlike nsec, nothing migrates it into encrypted storage. A node carrying it only in the DB blob would load it into memory once, rewrite the blob without it, and lose it on the next restart, breaking upstream auth. It is node-scoped config that really belongs on a provider, not a vault secret, and it has no encrypted home yet. Remove it from SECRET_FIELDS so it stays in the blob exactly as before; redaction on read and ignore-on-write in the admin settings endpoint are unchanged. Encrypting it is follow-up work. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>