mirror of
https://github.com/NginxProxyManager/nginx-proxy-manager.git
synced 2026-10-06 07:14:37 +01:00
fix: omit certificate_key from certificate API responses
The private key of custom certificates was returned in meta by GET /api/nginx/certificates and GET /api/nginx/certificates/{id}. Add meta.certificate_key to omissions(), the same way meta.dns_provider_credentials is hidden. The key stays in the database and is still written to /data/custom_ssl on upload.
This commit is contained in:
@@ -25,7 +25,7 @@ const certbotLogsDir = "/data/logs";
|
||||
const certbotWorkDir = "/tmp/letsencrypt-lib";
|
||||
|
||||
const omissions = () => {
|
||||
return ["is_deleted", "owner.is_deleted", "meta.dns_provider_credentials"];
|
||||
return ["is_deleted", "owner.is_deleted", "meta.dns_provider_credentials", "meta.certificate_key"];
|
||||
};
|
||||
|
||||
const internalCertificate = {
|
||||
|
||||
@@ -69,6 +69,9 @@ describe('Certificates endpoints', () => {
|
||||
}).then((data) => {
|
||||
cy.validateSwaggerSchema('get', 200, '/nginx/certificates', data);
|
||||
expect(data.length).to.be.greaterThan(0);
|
||||
const cert = data.find((c) => c.id === certID);
|
||||
expect(cert.meta).to.have.property('certificate');
|
||||
expect(cert.meta).to.not.have.property('certificate_key');
|
||||
|
||||
// Delete cert
|
||||
cy.task('backendApiDelete', {
|
||||
|
||||
Reference in New Issue
Block a user