fix(security #15): read API keys from process.env at request time
Module-level const assignments (SONARR_API_KEY, RADARR_API_KEY, SABNZBD_API_KEY, EMBY_URL, EMBY_API_KEY) captured values at startup and would not pick up rotated credentials without a restart. Replaced all module-level captures in emby.js, sabnzbd.js, sonarr.js, radarr.js, and dashboard.js with inline process.env reads at each call site. A process restart is still needed for dotenv-loaded values but environment-injected vars (Docker, Kubernetes) are re-read live.
This commit is contained in:
@@ -4,18 +4,15 @@ const router = express.Router();
|
||||
const requireAuth = require('../middleware/requireAuth');
|
||||
const sanitizeError = require('../utils/sanitizeError');
|
||||
|
||||
const SABNZBD_URL = process.env.SABNZBD_URL;
|
||||
const SABNZBD_API_KEY = process.env.SABNZBD_API_KEY;
|
||||
|
||||
router.use(requireAuth);
|
||||
|
||||
// Get current queue
|
||||
router.get('/queue', async (req, res) => {
|
||||
try {
|
||||
const response = await axios.get(`${SABNZBD_URL}/api`, {
|
||||
const response = await axios.get(`${process.env.SABNZBD_URL}/api`, {
|
||||
params: {
|
||||
mode: 'queue',
|
||||
apikey: SABNZBD_API_KEY,
|
||||
apikey: process.env.SABNZBD_API_KEY,
|
||||
output: 'json'
|
||||
}
|
||||
});
|
||||
@@ -28,10 +25,10 @@ router.get('/queue', async (req, res) => {
|
||||
// Get history
|
||||
router.get('/history', async (req, res) => {
|
||||
try {
|
||||
const response = await axios.get(`${SABNZBD_URL}/api`, {
|
||||
const response = await axios.get(`${process.env.SABNZBD_URL}/api`, {
|
||||
params: {
|
||||
mode: 'history',
|
||||
apikey: SABNZBD_API_KEY,
|
||||
apikey: process.env.SABNZBD_API_KEY,
|
||||
output: 'json',
|
||||
limit: req.query.limit || 50
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user