RexSystem1 voteoriginally by @DarkRTA on GitHub1 reply
To be honest, this feels like security theater because nothing stops a server admin from disabling the code and reading their own DB anyway.
I guess you could get marginal security improvements in the event of a compromise but I doubt this would be possible to scale up in a secure manner.
RexSystem1 voteoriginally by @Darker-Ink on GitHub
Like what I said in the other comment, it can call the chat encryption/decryption service to decrypt the chats that is then dumped into Meilisearch.
I do not believe this solves anything though, as you'd be dumping plaintext messages into Meilisearch, which makes message encryption pointless. Meilisearch becomes its own attack surface, and an attacker wouldn't even need DB access to get to the plaintext. So what would encrypting the messages in the database actually solve here?
Thread
Comment by @DarkRTA
Comment by @Darker-Ink