-- API keys (the OpenSubsonic apiKey) are stored as their sha256, hex, the -- same way session tokens are. A leaked database row or backup no longer -- hands out working keys. Existing keys are hashed in place, so every -- Subsonic client keeps working; the key itself can no longer be shown -- again, only replaced (M462 #4983). ALTER TABLE users ADD COLUMN api_token_hash text; UPDATE users SET api_token_hash = encode(sha256(convert_to(api_token, 'UTF8')), 'hex'); ALTER TABLE users ALTER COLUMN api_token_hash SET NOT NULL; ALTER TABLE users ADD CONSTRAINT users_api_token_hash_key UNIQUE (api_token_hash); ALTER TABLE users DROP COLUMN api_token;