Skip to content

chore: decide whether the CrowdSec config export should include stored secrets #1534

Description

@Wikid82

What: the CrowdSec config editor no longer lists or reads the CrowdSec account/credential files, but ExportConfig (backend/internal/api/handlers/crowdsec_handler.go) still archives the whole data directory, so an admin download of the export contains them (and the bouncer key). This is an authenticated admin feature, so it is not a vulnerability, but it is inconsistent with the editor behaviour.
Suggested approach: decide whether export should omit stored secrets (reusing the editor's hidden-file rule) or keep them for full-fidelity backups with an explicit user-facing note/option; if omitted, check that import/restore still works without them. Related: #1532 (export size).
Found while working on #1525/#1526 follow-ups. Severity: low.

Activity

  1. self-assigned this
    on Oct 10, 2026
  2. closed this as completedby moving to Done in Charonon Oct 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

backendServer-side codecrowdsecCrowdSec integration

Projects

  • Status
    Done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions