Encryption (server/crypto.ts):
- AES-256-GCM with a key derived from ENCRYPTION_KEY, falling back to
SESSION_SECRET so existing deployments need no new configuration
- stored format enc:v1:<iv>:<tag>:<data>; encryption is idempotent and
decryption passes legacy plaintext through unchanged, so nothing breaks
mid-migration
- tampered data or a changed key raises an explicit error instead of
returning garbage
- encrypt/decrypt is confined to the storage layer: group writes encrypt
smtpPassword (decrypted only in emailService at connection time, never sent
to the client), NocoDB config writes encrypt apiToken and reads decrypt it
so the invoice verification and the admin page behave as before
- startup migration sweep encrypts secrets already stored in plaintext,
idempotently; the active-config log line no longer prints the token
Mail history (supplier_mail_logs):
- every send attempt is recorded: delivery, store, supplier, recipient,
subject, status sent/failed with error, message id, user id and name;
a logging failure never fails the send itself
- GET /api/supplier-mail-logs restricted to the user's stores (admin may
filter by store)
- on the reconciliation page the mail icon turns green once a request has
been sent, with the date and sender in the tooltip; clicking again resends
- table created in init.sql, versioned migrations and the production
startup migration, with delivery/group indexes
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FHdE9nEh8zHhQNGpCgrtYe