coolify/app/Http/Controllers/Api
Andras Bacsai 8dc79f4ed6 fix(api): expose nested server secrets for privileged tokens
Add `exposeNestedServerSecrets()` to Applications, Databases, and
Services controllers so that `read:sensitive`/`root` tokens see
sentinel and logdrain fields on eager-loaded Server + ServerSetting
relations.

ServicesController handles both single models and Eloquent Collections
(listing endpoint passes a Collection per project).

Tests tightened to use JSON-key assertions (`"field":`) to avoid false
positives from field names appearing in values.
2026-04-30 11:49:15 +02:00
..
ApplicationsController.php fix(api): expose nested server secrets for privileged tokens 2026-04-30 11:49:15 +02:00
CloudProviderTokensController.php feat(observability): add structured audit log channel for API and webhook events 2026-04-28 14:50:37 +02:00
DatabasesController.php fix(api): expose nested server secrets for privileged tokens 2026-04-30 11:49:15 +02:00
DeployController.php feat(observability): add structured audit log channel for API and webhook events 2026-04-28 14:50:37 +02:00
GithubController.php feat(observability): add structured audit log channel for API and webhook events 2026-04-28 14:50:37 +02:00
HetznerController.php feat(observability): add structured audit log channel for API and webhook events 2026-04-28 14:50:37 +02:00
OpenApi.php feat(api): Improve OpenAPI spec and add rate limit handling for Hetzner 2025-12-11 12:12:43 +01:00
OtherController.php feat(mcp): add MCP server with read-only tools for Coolify resources 2026-04-29 10:30:43 +02:00
ProjectController.php feat(observability): add structured audit log channel for API and webhook events 2026-04-28 14:50:37 +02:00
ResourcesController.php feat(auth): implement comprehensive authorization checks across API controllers 2025-08-23 18:51:10 +02:00
ScheduledTasksController.php feat(observability): add structured audit log channel for API and webhook events 2026-04-28 14:50:37 +02:00
SecurityController.php feat(observability): add structured audit log channel for API and webhook events 2026-04-28 14:50:37 +02:00
ServersController.php fix(api): hide sensitive fields by default, expose via makeVisible for privileged tokens 2026-04-30 11:28:06 +02:00
ServicesController.php fix(api): expose nested server secrets for privileged tokens 2026-04-30 11:49:15 +02:00
TeamController.php fix(security): harden model assignment and sensitive data handling 2026-03-29 20:56:04 +02:00