- Shipped
- 23 سبتمبر 2026 في 11:27 م UTC
- صاحب البلاغ
- Kamo
- Commit
- 928b506
5de57705 added OrgDomain.dkimPrivateKey — the key that signs a domain's transactional mail — with a comment saying it is never sent to the browser, but nothing made that true: Organization serializes its domains, so any response carrying an org or a domain would publish it. **************** has been red on main since (the library has no CI to notice). @JsonIgnore, as the guard asks. Every reader (securityservice's DkimAuthorizationService, emailservice's EmailTemplateService) signs server-side from the entity, so nothing loses the key. One production domain already holds a generated key.
