- Порезанный
- 23 сентября 2026 г. в 23:27 UTC
- Автор
- Kamo
- Обещать
- 928b506
5de57705 added OrgDomain.dkimPrivateKey — the key that signs a domain's transactional mail — with a comment saying it is never sent to the browser, but nothing made that true: Organization serializes its domains, so any response carrying an org or a domain would publish it. **************** has been red on main since (the library has no CI to notice). @JsonIgnore, as the guard asks. Every reader (securityservice's DkimAuthorizationService, emailservice's EmailTemplateService) signs server-side from the entity, so nothing loses the key. One production domain already holds a generated key.
