Skip to content

Security: remove client-side UploadThing credentials #298

Description

@bobtista

Summary

Remove the legacy UploadThing credential flow from the desktop client. This path affected development artifacts and was not present in the last public release.

Scope

  • Remove CI credential injection and client decoding.
  • Disable upload and delete operations while preserving public-link imports.
  • Make history removal local-only.
  • Add tests and update developer documentation.

Follow-up

Rotate the credential, remove obsolete repository secrets, and privately review account activity. Future uploads require short-lived server-issued authorization or signed URLs.

Related: #233, #238

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions