Add Resend API key to admin-configurable Server secrets

Was only ever settable via .env - now follows the same pattern as
Cloudflare Turnstile: SystemSecretKey.RESEND_API_KEY + a META entry
covers storage/encryption/frontend rendering automatically (the
Settings UI's Server secrets box is fully data-driven off this list).
Wired the register/login/resend-verification/request-password-reset
route handlers to use get_effective_settings so an admin-set key
actually reaches the emails those flows send, not just .env's value.

Co-Authored-By: Claude Sonnet 5 <[email protected]>
This commit is contained in:
2026-08-05 20:44:35 -04:00
co-authored by Claude Sonnet 5
parent a9ac6454c6
commit 3e1fa1845b
5 changed files with 49 additions and 18 deletions
+2 -1
View File
@@ -401,7 +401,8 @@ function ServerSecretsBox() {
<KeyRound className="h-4 w-4" aria-hidden /> Server secrets
</div>
<p className="mt-1 text-sm text-slate-500">
Server-wide configuration shared by every visitor, used for Cloudflare Turnstile CAPTCHA.
Server-wide configuration shared by every visitor: Cloudflare Turnstile CAPTCHA and the
Resend API key used for transactional security email.
</p>
{isLoading ? (