feat(server): enhance secret management and logging functionality

- Added SCRUNNER_SECRETS_KEY to README as a required variable for production.
- Implemented redaction of sensitive information in logs across various components.
- Enhanced script execution functions to include an owner parameter for better secret management.
- Introduced a secrets API in the script sandbox for retrieving and managing secrets.
- Updated UI components to support owner selection for script execution and secret management.
This commit is contained in:
2026-08-14 22:11:03 +07:00
parent 94aa5b2efa
commit 3e4d5f443d
19 changed files with 886 additions and 39 deletions
+50
View File
@@ -0,0 +1,50 @@
async function getSecret(ctx) {
const name = ctx.config?.name;
if (typeof name !== "string" || name.length === 0) {
throw new Error("config.name is required");
}
const as =
typeof ctx.config?.as === "string" && ctx.config.as.length > 0
? ctx.config.as
: name;
const value = await $secrets.get(name);
const base =
ctx != null && typeof ctx === "object" && !Array.isArray(ctx) ? { ...ctx } : {};
const data =
base.data != null && typeof base.data === "object" && !Array.isArray(base.data)
? { ...base.data }
: {};
data[as] = value;
return { ...base, data };
}
getSecret.meta = {
description:
"Load a named secret for this workflow owner into ctx.data. The value is wrapped and redacted in logs.",
config: {
name: {
type: "string",
required: true,
description: "Secret name (per owner)",
},
as: {
type: "string",
required: false,
description: "ctx.data field to write (defaults to name)",
},
},
input: {},
output: {
data: {
type: "object",
description: "Previous ctx.data plus the retrieved Secret at [as]",
},
},
example: {
data: {},
config: { name: "ntfy_token", as: "ntfyToken" },
},
};
export default getSecret;