fix(api): expose nested server secrets for privileged tokens

Add `exposeNestedServerSecrets()` to Applications, Databases, and
Services controllers so that `read:sensitive`/`root` tokens see
sentinel and logdrain fields on eager-loaded Server + ServerSetting
relations.

ServicesController handles both single models and Eloquent Collections
(listing endpoint passes a Collection per project).

Tests tightened to use JSON-key assertions (`"field":`) to avoid false
positives from field names appearing in values.
This commit is contained in:
Andras Bacsai
2026-04-30 11:49:15 +02:00
parent e828058755
commit 8dc79f4ed6
4 changed files with 116 additions and 6 deletions
@@ -49,11 +49,39 @@ class DatabasesController extends Controller
'mariadb_password',
'mariadb_root_password',
]);
$this->exposeNestedServerSecrets($database);
}
return serializeApiResponse($database);
}
/**
* Expose sensitive fields on eager-loaded nested Server + ServerSetting
* relations for callers with the `read:sensitive` or `root` token ability.
*/
private function exposeNestedServerSecrets($model): void
{
$server = $model->destination?->server ?? null;
if (! $server) {
return;
}
$server->makeVisible([
'logdrain_axiom_api_key',
'logdrain_newrelic_license_key',
]);
$settings = $server->settings ?? null;
if ($settings) {
$settings->makeVisible([
'sentinel_token',
'sentinel_custom_url',
'logdrain_newrelic_license_key',
'logdrain_axiom_api_key',
'logdrain_custom_config',
'logdrain_custom_config_parser',
]);
}
}
#[OA\Get(
summary: 'List',
description: 'List all databases.',