Files
oh-my-pi/packages
iacore fcf6d65140 fix(coding-agent): resolve the secret placeholder key lazily for builtin credential entries
Appending builtinCredentialSecretEntries() unconditionally made every
secrets.enabled session carry a regex obfuscate entry, so
secretEntriesNeedPlaceholderKey was always true and startup always
created secret-placeholder.key — nullifying the replace-only/no-secret
key-avoidance path and failing headless runs on an unwritable config
root for a feature they never use.

Only configured entries now force startup key creation. The built-in
credential pattern matches dynamically, so SecretObfuscator accepts a
key provider resolved once on the first actual credential match, via
the new getSecretPlaceholderKeySync (never throws: degrades to a
process-ephemeral key with a warning when the key file is unwritable).

Also moves both CHANGELOG entries from the released 17.1.7 sections to
[Unreleased].
2026-07-31 13:38:09 +08:00
..
2026-07-30 07:58:50 +02:00
2026-07-30 07:58:50 +02:00
2026-07-30 07:58:50 +02:00
2026-07-30 07:58:50 +02:00
2026-07-30 07:58:50 +02:00
2026-07-30 07:58:50 +02:00
2026-07-30 07:58:50 +02:00
2026-07-30 07:58:50 +02:00
2026-07-30 07:58:50 +02:00
2026-07-30 07:58:50 +02:00