isUsable() checked only "is SECRETS_KEY nonempty", so a set-but-malformed key (wrong length, garbage base64) read back as usable even though encrypter() rejects it two lines below. EditMailbox::save() and MailboxTester::run() both gate on isUsable() specifically to avoid an uncaught RuntimeException reaching the operator; a lying isUsable() meant that guard did not fire in exactly the configuration it exists for. Both methods now read resolveKey() — the base64: prefix, the raw-base64 path, the 32-byte check — so they cannot disagree about a value either one is given. SecretVault::isUsable() and the secrets console page's "no key" banner both delegate down to this and are covered here too, not assumed to inherit the fix correctly. |
||
|---|---|---|
| .. | ||
| Billing | ||
| Deployment | ||
| Dns | ||
| Maintenance | ||
| Monitoring | ||
| Proxmox | ||
| Secrets | ||
| Ssh | ||
| Stripe | ||
| Traefik | ||
| Traffic | ||
| Wireguard | ||