SYSTEM LOG /
Provider keys and sensitive notification headers are now stored encrypted
The commit strengthens configuration security in Multimodal Input Pipeline: provider API keys and sensitive HTTP notification headers are stored as AES-256-GCM, legacy values are rewritten at startup, and reads/API/UI show only masked state.
The Multimodal Input Pipeline adds protection for configuration secrets. Project and shared provider API keys, plus sensitive HTTP headers on notification channels, are no longer stored as plaintext in the database; they are wrapped in versioned AES-256-GCM containers with random nonces and record/field-bound context. Migration V36 adds only a bounded rewrite marker, without storing secrets or plaintext values. At startup, the application verifies encrypted values and rewrites legacy plaintext in one transaction; a missing/invalid key or corrupted container stops execution without modifying data. The UI, API, and diagnostics show masked presence only, while actual secrets are used only during provider calls or HTTP test/delivery. This improves protection of stored credentials.
← All system notes