fix(dkv): return username in GET /dkv/config response
Tessera CI/CD / Lint & Type Check (push) Successful in 40s
Tessera CI/CD / Tests (push) Successful in 37s
Tessera CI/CD / Build & Publish Images (push) Successful in 22s

loadConfig used CONFIG_SAFE_SELECT which excludes encryptedInboxCreds entirely,
so username was never returned to the frontend — form always showed empty username.

Added getConfigForApi() which loads the safe config + decrypts encryptedInboxCreds
to extract username (never password) and adds hasPassword boolean. Controller
getConfig now calls getConfigForApi instead of loadConfig.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-06-30 09:58:59 +02:00
parent a44e40f101
commit b5bf3ed8c0
2 changed files with 24 additions and 2 deletions
+2 -2
View File
@@ -55,12 +55,12 @@ export class DkvController {
// ─── Config ────────────────────────────────────────────────────────────────
/** GET /dkv/config — returns module config without encrypted credentials. 404 when not yet configured. */
/** GET /dkv/config — returns module config with username + hasPassword. 404 when not yet configured. */
@Get('config')
@Roles(Role.ADMIN, Role.SUPER_ADMIN)
async getConfig(@Req() req: any) {
const tenantId = this._requireTenant(req);
const config = await this.dkvService.loadConfig(tenantId);
const config = await this.dkvService.getConfigForApi(tenantId);
if (!config) {
throw new NotFoundException('DKV module not yet configured');
}
+22
View File
@@ -102,6 +102,28 @@ export class DkvService {
});
}
/**
* Load config for API response: safe fields + decrypted username + hasPassword flag.
* T-07-12: password is NEVER returned — only hasPassword boolean.
*/
async getConfigForApi(tenantId: string) {
const safe = await this.loadConfig(tenantId);
if (!safe) return null;
let username: string | null = null;
let hasPassword = false;
try {
const raw = await this.prisma.dkvModuleConfig.findUnique({ where: { tenantId } });
if (raw?.encryptedInboxCreds) {
const creds = JSON.parse(this.crypto.decrypt(raw.encryptedInboxCreds)) as { username?: string; password?: string };
username = creds.username ?? null;
hasPassword = Boolean(creds.password);
}
} catch { /* ignore decrypt errors — return empty username */ }
return { ...safe, username, hasPassword };
}
/**
* Upsert DKV module config for a tenant.
*