refactor: rename the encryption key to what it actually protects
CALENDAR_ENCRYPTION_KEY was named after the calendar module because that module needed encryption first, in Phase 5. Every feature since has shared the same key -- SMTP, the DKV and tender mailboxes, and as of today the LDAP bind password -- so the name has been describing one of five users rather than the thing itself, and each new feature inherited the confusion. TESSERA_ENCRYPTION_KEY is the name now. The old one is still read, because renaming outright would stop every existing installation at the next start: their .env carries the old name, and compose was just made to fail hard on a missing key. When only the old name is present the API logs a deprecation warning naming both, and when both are set the new one wins -- otherwise a half-migrated .env would encrypt with one key and decrypt with the other. CalendarCryptoService becomes CryptoService in its own global CryptoModule. Four modules used to import CalendarModule purely to reach the provider, which read as a dependency on calendars where there was none; that import is gone. Compose keeps the hard failure: without either name the stack refuses to start. Verified in both files for all three cases -- neither name set (abort), only the old name (starts), only the new name (starts). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -12,11 +12,11 @@ import {
|
||||
* email-alert.adapter.spec — Task 1 (test-first, TDD) proof for the generic
|
||||
* link/subject extraction (D-04): pure functions only, no I/O, mirroring
|
||||
* cosinex.adapter.spec.ts's pure-function spec style. Task 2 adds
|
||||
* fetchTenders() fan-out coverage (mocked PrismaService/CalendarCryptoService/
|
||||
* fetchTenders() fan-out coverage (mocked PrismaService/CryptoService/
|
||||
* inbox providers — no live DB/network I/O).
|
||||
*/
|
||||
|
||||
/** Fake CalendarCryptoService — deterministic reversible encode, not real AES. */
|
||||
/** Fake CryptoService — deterministic reversible encode, not real AES. */
|
||||
function makeFakeCrypto() {
|
||||
return {
|
||||
encrypt: vi.fn((plaintext: string) => `enc:${Buffer.from(plaintext).toString('base64')}`),
|
||||
|
||||
@@ -1,7 +1,8 @@
|
||||
import { Injectable, Logger } from '@nestjs/common';
|
||||
import { CryptoService } from '../../crypto/crypto.service';
|
||||
import * as cheerio from 'cheerio';
|
||||
import { createHash } from 'crypto';
|
||||
import { CalendarCryptoService } from '../../calendar/crypto.service';
|
||||
|
||||
import { ExchangeInboxProvider } from '../../inbox/exchange-inbox.provider';
|
||||
import { ImapProvider } from '../../inbox/imap.provider';
|
||||
import type { InboxConfig, InboxMessage } from '../../inbox/inbox-provider.interface';
|
||||
@@ -123,7 +124,7 @@ export class EmailAlertAdapter implements TenderSourceAdapter {
|
||||
|
||||
constructor(
|
||||
private readonly prisma: PrismaService,
|
||||
private readonly crypto: CalendarCryptoService,
|
||||
private readonly crypto: CryptoService,
|
||||
private readonly imapProvider: ImapProvider,
|
||||
private readonly exchangeProvider: ExchangeInboxProvider,
|
||||
) {}
|
||||
|
||||
Reference in New Issue
Block a user