Commit Graph

4 Commits

Author SHA1 Message Date
can1357 5aa599f9ac fix(cli): treat cleared (empty-string) credentials as unset in config list
The settings panel persists "" when a credential is cleared and renders
that as unset; config list now uses the same semantics instead of
masking the empty string as a configured credential.
2026-07-26 15:41:29 +02:00
Wolfgang Schoenberger 3589d9c679 style(coding-agent): format credential output tests 2026-07-26 03:13:38 -07:00
Wolfgang Schoenberger 3e1679f584 fix(cli): keep the Hindsight URL readable and redact only set credentials
The credential pass marked `hindsight.apiUrl` secret instead of
`hindsight.apiToken`: both share `condition: "hindsightActive"` and the flag
landed on the wrong one, so the settings panel masked an ordinary endpoint. The
token keeps its masking through the `credential` marker.

`config list` also redacted on classification alone, so a fresh configuration
reported every unset credential as though one were stored. Redaction now
depends on a value being present.

The suite asserted classification and panel metadata only, so both output
branches could be deleted while every test passed, which is how the wrong flag
shipped. It now drives `runConfigCommand` and reads the real human and JSON
output.
2026-07-26 02:58:38 -07:00
Wolfgang Schoenberger 914afc0d6c fix(cli): redact credential settings in config list
omp config list printed every configured value, including auth.broker.token,
searxng.token, searxng.basicPassword and dev.autoqaPush.token, in both the
human and --json output. Nobody asked for those specific credentials; the
command dumps everything.

Credentials are marked with a top-level credential flag rather than ui.secret,
because four of them have no settings-panel entry and so have nowhere to put a
UI-level flag. isCredential is the single accessor both the CLI and the panel
consult, so the two spellings cannot produce different behaviour on different
surfaces.

Human output shows dots. JSON omits value and marks the entry redacted instead
of substituting a placeholder, which a consumer could not distinguish from a
real value and might write back.

config get <path> is deliberately unchanged: that is an explicit request for a
single value, and masking it would break a retrieval API with no way to read
your own token back.
2026-07-26 02:58:38 -07:00