Transparent server-side encryption with stable master key

FixSecurityService
Shipped
March 23, 2026 at 10:35 PM UTC
Author
Kamo
Commit
be03417

- Add permanent notes.master-encryption-key to ConfigMap (was generating a random key on each pod restart, making old notes undecryptable) - Always encrypt content on create/update, always decrypt on read - Extract decryptDTO helper for consistent decryption across getNote, getAllNotes, and searchNotes - Notes encrypted with a lost key show null content (unrecoverable) but their data is preserved in DB for potential future recovery

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing