fixthestatusquo / archive-proca-backend

Backend for the ultimate petition/campaigning tool
GNU Affero General Public License v3.0
7 stars 2 forks source link

Secure/audit key changes #128

Open tttp opened 3 years ago

tttp commented 3 years ago

Setting up the encryption key is a very sensitive operation. I should be made much more visible:

It's good to keep a log of the key changes, either as an audit log, or at least add a "owner" to the encryption key (key to the user), so we know who changed it