diff --git a/apps/api/src/dkv/dkv.controller.ts b/apps/api/src/dkv/dkv.controller.ts index 391fe2d..6ecc90d 100644 --- a/apps/api/src/dkv/dkv.controller.ts +++ b/apps/api/src/dkv/dkv.controller.ts @@ -55,12 +55,12 @@ export class DkvController { // ─── Config ──────────────────────────────────────────────────────────────── - /** GET /dkv/config — returns module config without encrypted credentials. 404 when not yet configured. */ + /** GET /dkv/config — returns module config with username + hasPassword. 404 when not yet configured. */ @Get('config') @Roles(Role.ADMIN, Role.SUPER_ADMIN) async getConfig(@Req() req: any) { const tenantId = this._requireTenant(req); - const config = await this.dkvService.loadConfig(tenantId); + const config = await this.dkvService.getConfigForApi(tenantId); if (!config) { throw new NotFoundException('DKV module not yet configured'); } diff --git a/apps/api/src/dkv/dkv.service.ts b/apps/api/src/dkv/dkv.service.ts index 302b1a3..61a352c 100644 --- a/apps/api/src/dkv/dkv.service.ts +++ b/apps/api/src/dkv/dkv.service.ts @@ -102,6 +102,28 @@ export class DkvService { }); } + /** + * Load config for API response: safe fields + decrypted username + hasPassword flag. + * T-07-12: password is NEVER returned — only hasPassword boolean. + */ + async getConfigForApi(tenantId: string) { + const safe = await this.loadConfig(tenantId); + if (!safe) return null; + + let username: string | null = null; + let hasPassword = false; + try { + const raw = await this.prisma.dkvModuleConfig.findUnique({ where: { tenantId } }); + if (raw?.encryptedInboxCreds) { + const creds = JSON.parse(this.crypto.decrypt(raw.encryptedInboxCreds)) as { username?: string; password?: string }; + username = creds.username ?? null; + hasPassword = Boolean(creds.password); + } + } catch { /* ignore decrypt errors — return empty username */ } + + return { ...safe, username, hasPassword }; + } + /** * Upsert DKV module config for a tenant. *