Something went wrong. Try again.
Barazo AppView backend barazo.forum
Something went wrong. Try again.
feat(security): encrypt PLC DID keys at rest with AES-256-GCM (#71) master
Community signing and rotation keys were stored as plaintext in the community_settings table. These keys control the community's AT Protocol identity -- a database leak would allow DID takeover. Add application-level encryption using AES-256-GCM with HKDF key derivation from the AI_ENCRYPTION_KEY environment variable (KEK). Keys are now encrypted before DB write in the setup service.
Author Guido X Jansen Committer GitHub Date (Feb 20, 2026, 9:52 PM UTC) Commit 271a3cac 271a3cac0c426a7fc81b0727f59e2f9885eb5731 Parent 84e17265 84e17265bfde02fb85ff13f9f5deea360eb51988