- Expediere
- 23 septembrie 2026 la 23:27 UTC
- Autor
- Kamo
- Comite
- 928b506
5de57705 added OrgDomain.dkimPrivateKey — the key that signs a domain's transactional mail — with a comment saying it is never sent to the browser, but nothing made that true: Organization serializes its domains, so any response carrying an org or a domain would publish it. **************** has been red on main since (the library has no CI to notice). @JsonIgnore, as the guard asks. Every reader (securityservice's DkimAuthorizationService, emailservice's EmailTemplateService) signs server-side from the entity, so nothing loses the key. One production domain already holds a generated key.
