Store the key encrypted in the DB (not git) and proxy OMDb posters so clients never see the API key.
Co-authored-by: Cursor <cursoragent@cursor.com>