From a54b73f1535efc357cea46961e84c73f76661e7c Mon Sep 17 00:00:00 2001 From: Amit Yadav Date: Fri, 25 Sep 2026 20:35:32 +0530 Subject: [PATCH] fix: omit certificate_key from certificate API responses The private key of custom certificates was returned in meta by GET /api/nginx/certificates and GET /api/nginx/certificates/{id}. Add meta.certificate_key to omissions(), the same way meta.dns_provider_credentials is hidden. The key stays in the database and is still written to /data/custom_ssl on upload. --- backend/internal/certificate.js | 2 +- test/cypress/e2e/api/Certificates.cy.js | 3 +++ 2 files changed, 4 insertions(+), 1 deletion(-) diff --git a/backend/internal/certificate.js b/backend/internal/certificate.js index 963d2bb6a..9a14f5893 100644 --- a/backend/internal/certificate.js +++ b/backend/internal/certificate.js @@ -25,7 +25,7 @@ const certbotLogsDir = "/data/logs"; const certbotWorkDir = "/tmp/letsencrypt-lib"; const omissions = () => { - return ["is_deleted", "owner.is_deleted", "meta.dns_provider_credentials"]; + return ["is_deleted", "owner.is_deleted", "meta.dns_provider_credentials", "meta.certificate_key"]; }; const internalCertificate = { diff --git a/test/cypress/e2e/api/Certificates.cy.js b/test/cypress/e2e/api/Certificates.cy.js index 25d1b8c41..7d75d40cf 100644 --- a/test/cypress/e2e/api/Certificates.cy.js +++ b/test/cypress/e2e/api/Certificates.cy.js @@ -69,6 +69,9 @@ describe('Certificates endpoints', () => { }).then((data) => { cy.validateSwaggerSchema('get', 200, '/nginx/certificates', data); expect(data.length).to.be.greaterThan(0); + const cert = data.find((c) => c.id === certID); + expect(cert.meta).to.have.property('certificate'); + expect(cert.meta).to.not.have.property('certificate_key'); // Delete cert cy.task('backendApiDelete', {