```Removed: -### ChecksRemoved: -Removed: -- ☑ I searched existing issues.Removed: -- ☑ I wrote this report in my own words, except for direct translation if needed.Removed: -
Show
Self-hosted: Adding an invalid private key for Bluesky OAuth causes the entire system to crash
Summary
When I was setting up the Bluesky OAuth for my self-hosted instance, I had added a private key that the system didn't like and caused the entire system to crash due to a lack of safety checks in src/api/bluesky/BlueskyOAuthService.ts.
Steps to reproduce
Create a new private signed key using openSSL that's not the correct typing for BlueSky's OAuth.
Copy the private key
Paste the private key into the New Private Key field.
Name the key in the New signing key ID field.
Save runtime integrations
Reload any of the Fluxer instance and see it fail to load due to the error from the API container.
Alternatively
Paste any random value into the New Private Key field.
Name the key in the New signing key ID field.
Save runtime integrations
Reload any of the Fluxer instance and see it fail to load due to the error from the API container.
{
"level": "error",
"time": "2026-06-16T23:01:59.202Z",
"service": "errors",
"env": "production",
"err": {
"type": "JwkError",
"message": "Invalid input",
"stack": "TypeError: Invalid input
at JoseKey.fromImportable (/usr/src/app/fluxer_api/node_modules/.pnpm/@bluesky-social+jwk-jose@0.1.11/node_modules/@bluesky-social/jwk-jose/src/jose-key.ts:191:13)
at <anonymous> (/usr/src/app/fluxer_api/src/api/bluesky/BlueskyOAuthService.ts:36:20)
at Array.map (<anonymous>)
at BlueskyOAuthService.create (/usr/src/app/fluxer_api/src/api/bluesky/BlueskyOAuthService.ts:30:16)
at resolveBlueskyOAuthService (/usr/src/app/fluxer_api/src/api/middleware/ServiceRegistry.ts:229:60)
at async Object.handler (/usr/src/app/fluxer_api/src/api/middleware/ServiceMiddleware.ts:435:30)
at async dispatch (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/compose.js:22:17)
at async handler (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/hono-base.js:118:39)
at async dispatch (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/compose.js:22:17)
at async Object.handler (/usr/src/app/fluxer_api/src/api/middleware/RequireClientIpMiddleware.ts:46:3)",
"code": "ERR_JWK_INVALID"
},
"msg": "Unhandled error occurred"
}
Original by Rex
Show
Self-hosted: Adding an invalid private key for Bluesky OAuth causes the entire system to crash
Summary
When I was setting up the Bluesky OAuth for my self-hosted instance, I had added a private key that the system didn't like and caused the entire system to crash due to a lack of safety checks in src/api/bluesky/BlueskyOAuthService.ts.
Steps to reproduce
Create a new private signed key using openSSL that's not the correct typing for BlueSky's OAuth.
Copy the private key
Paste the private key into the New Private Key field.
Name the key in the New signing key ID field.
Save runtime integrations
Reload any of the Fluxer instance and see it fail to load due to the error from the API container.
Alternatively
Paste any random value into the New Private Key field.
Name the key in the New signing key ID field.
Save runtime integrations
Reload any of the Fluxer instance and see it fail to load due to the error from the API container.