feat(api): derive stable placeholder names for hidden profiles (#3224)

This commit is contained in:
Hampus
2026-10-05 16:57:25 +02:00
committed by GitHub
parent 02c82f0038
commit 3093e7334b
30 changed files with 629 additions and 65 deletions
@@ -78,6 +78,10 @@ Sudo mode JWTs, as a raw HS256 key. Changing it ends every active sudo mode sess
Connection initiation tokens and harvest download links. Changing it invalidates connection initiation tokens not yet verified and harvest download links already issued.
#### `FLUXER_PROFILE_PSEUDONYM_SECRET`
Derives the stable placeholder name and tag that other users see while an account's profile is hidden. Must be byte-identical on `api`, `worker`, and `users-shard`, or the same account shows two different names. Changing it gives every hidden profile a new placeholder. `api` and `worker` refuse to start without it when `FLUXER_ENV` is `production`. `users-shard` refuses to start without it unless `FLUXER_ENV` is `development` or `test`.
#### `FLUXER_GATEWAY_RPC_AUTH_TOKEN`
Internal RPC between the API and the Gateway. Must be byte-identical on `api`, `worker`, and `gateway`.
@@ -75,6 +75,14 @@ To write it by hand, run the generator in a shell the same way:
printf '\nFLUXER_MEDIA_PROXY_UPLOAD_RELAY_SECRET_BASE64=%s\n' "$(openssl rand -base64 32)" >> .env
```
The refreshed stack requires `FLUXER_PROFILE_PSEUDONYM_SECRET` on `api`, `worker`, and `users-shard`. `--update` replaces a missing or `CHANGE_ME` value with 64 hex characters. Without it, Compose commands fail with `set FLUXER_PROFILE_PSEUDONYM_SECRET in .env`.
To write it by hand, run the generator in a shell the same way:
```bash
printf '\nFLUXER_PROFILE_PSEUDONYM_SECRET=%s\n' "$(openssl rand -hex 32)" >> .env
```
## The script is the reference
Read the [Linux and macOS installer](https://fluxer.dev/install.sh) or [Windows installer](https://fluxer.dev/install.ps1) before running it.
+2
View File
@@ -173,6 +173,7 @@ $FluxerBackupVolumes = @(
$FluxerUpgradeSecretKeys = @(
@{Name = 'FLUXER_ERLANG_COOKIE'; Kind = 'hex'}
@{Name = 'FLUXER_MEDIA_PROXY_UPLOAD_RELAY_SECRET_BASE64'; Kind = 'base64'}
@{Name = 'FLUXER_PROFILE_PSEUDONYM_SECRET'; Kind = 'hex'}
)
$FluxerSecretKeys = @(
@@ -181,6 +182,7 @@ $FluxerSecretKeys = @(
@{Name = 'FLUXER_S3_SECRET_KEY'; Kind = 'hex'}
@{Name = 'FLUXER_SUDO_MODE_SECRET'; Kind = 'hex'}
@{Name = 'FLUXER_CONNECTION_INITIATION_SECRET'; Kind = 'hex'}
@{Name = 'FLUXER_PROFILE_PSEUDONYM_SECRET'; Kind = 'hex'}
@{Name = 'FLUXER_GATEWAY_RPC_AUTH_TOKEN'; Kind = 'hex'}
@{Name = 'FLUXER_ERLANG_COOKIE'; Kind = 'hex'}
@{Name = 'FLUXER_MEDIA_PROXY_SECRET_KEY'; Kind = 'hex'}
+2
View File
@@ -110,6 +110,7 @@ MEILI_MASTER_KEY hex
FLUXER_S3_SECRET_KEY hex
FLUXER_SUDO_MODE_SECRET hex
FLUXER_CONNECTION_INITIATION_SECRET hex
FLUXER_PROFILE_PSEUDONYM_SECRET hex
FLUXER_GATEWAY_RPC_AUTH_TOKEN hex
FLUXER_ERLANG_COOKIE hex
FLUXER_MEDIA_PROXY_SECRET_KEY hex
@@ -1124,6 +1125,7 @@ fluxer_upgrade_secret_keys() {
cat <<'KEYS'
FLUXER_ERLANG_COOKIE hex
FLUXER_MEDIA_PROXY_UPLOAD_RELAY_SECRET_BASE64 base64
FLUXER_PROFILE_PSEUDONYM_SECRET hex
KEYS
}