fix: omit certificate_key from certificate API responses

The private key of custom certificates was returned in meta by GET /api/nginx/certificates and GET /api/nginx/certificates/{id}. Add meta.certificate_key to omissions(), the same way meta.dns_provider_credentials is hidden. The key stays in the database and is still written to /data/custom_ssl on upload.
This commit is contained in:
Amit Yadav
2026-09-25 20:35:32 +05:30
parent 2cfd3395cf
commit a54b73f153
2 changed files with 4 additions and 1 deletions
+1 -1
View File
@@ -25,7 +25,7 @@ const certbotLogsDir = "/data/logs";
const certbotWorkDir = "/tmp/letsencrypt-lib";
const omissions = () => {
return ["is_deleted", "owner.is_deleted", "meta.dns_provider_credentials"];
return ["is_deleted", "owner.is_deleted", "meta.dns_provider_credentials", "meta.certificate_key"];
};
const internalCertificate = {
+3
View File
@@ -69,6 +69,9 @@ describe('Certificates endpoints', () => {
}).then((data) => {
cy.validateSwaggerSchema('get', 200, '/nginx/certificates', data);
expect(data.length).to.be.greaterThan(0);
const cert = data.find((c) => c.id === certID);
expect(cert.meta).to.have.property('certificate');
expect(cert.meta).to.not.have.property('certificate_key');
// Delete cert
cy.task('backendApiDelete', {