diff --git a/.gitignore b/.gitignore index 2a99b57..14fa6c4 100644 --- a/.gitignore +++ b/.gitignore @@ -11,6 +11,14 @@ .localclaw/vault/ .smallclaw/credentials/ .smallclaw/vault/ +# The pattern above is anchored at the repo root, so per-user vaults one level down were never +# matched and every user's vault.key + vault.enc got committed — the master key sitting beside +# the file it decrypts. `.smallclaw/users/*/workspace/` (further down) covers that path today, +# but only for files not already tracked, which is exactly how these survived. Match a vault at +# any depth so a new one can never be added by a path nobody anticipated. +**/vault/vault.key +**/vault/vault.enc +**/vault/vault-audit.log .smallclaw/*_api_key.txt .smallclaw/*_api_token.txt .smallclaw/*-key.txt