Repository navigation
Load secret values in account editor - #323
Conversation
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
📝 WalkthroughWalkthroughTest mocks for ChangesAccount Secrets Test Updates
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Review rate limit: 0/1 reviews remaining, refill in 60 minutes.Comment |
|
🔎 Preview deployed: https://kody-pr-323.kentcdodds.workers.dev Worker: Mocks:
|
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/worker/src/app/handlers/account-secrets.ts`:
- Around line 903-928: The helper resolveAccountSecretDetail currently resolves
and attaches plaintext by calling resolveSecret (using parsed,
getSecretContextForAccountSecret and returning an AccountSecretDetail with
value), which bypasses the reauth flow; change it to stop resolving or returning
plaintext here—either remove the resolveSecret call entirely and return the
selected secret without a value, or gate attaching resolved.value behind an
explicit reauth check/token parameter (e.g., require a freshReauthToken flag or
call path from createAccountSecretRevealHandler) so only the reauth-protected
endpoint populates value; keep all other metadata from selected but do not
expose plaintext in resolveAccountSecretDetail.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: a2ff28f7-98a0-43d9-865a-0915ec748bfb
📒 Files selected for processing (4)
e2e/connect-secret.spec.tspackages/worker/client/routes/account-secrets.tsxpackages/worker/src/app/handlers/account-secrets.node.test.tspackages/worker/src/app/handlers/account-secrets.ts
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 2 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 5cc4e4e. Configure here.
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
There was a problem hiding this comment.
🧹 Nitpick comments (1)
packages/worker/src/app/handlers/account-secrets.node.test.ts (1)
38-38: 💤 Low valueConsider completing the
resolveSecretdefault mock to match the fullResolvedSecretshape.The mock currently omits
scope,allowedHosts,allowedCapabilities, andallowedPackages. While no test currently reaches the default mock (the reveal tests usemockResolvedValueOnce; the GET metadata test assertsresolveSecretis not called), an incomplete fallback can produce confusingundefinedaccesses if a future test exercises an unexpected handler path.♻️ Suggested completion
- resolveSecret: vi.fn(async () => ({ found: false, value: null })), + resolveSecret: vi.fn(async () => ({ + found: false, + value: null, + scope: null, + allowedHosts: [], + allowedCapabilities: [], + allowedPackages: [], + })),🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@packages/worker/src/app/handlers/account-secrets.node.test.ts` at line 38, The default mock for resolveSecret returns an incomplete ResolvedSecret shape which can cause undefined property access later; update the vi.fn default in the test so resolveSecret returns the full ResolvedSecret fields (include scope, allowedHosts, allowedCapabilities, allowedPackages in addition to found and value) with safe default values (e.g., null/empty array/empty string as appropriate) so any fallback invocation of resolveSecret has the complete shape.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Nitpick comments:
In `@packages/worker/src/app/handlers/account-secrets.node.test.ts`:
- Line 38: The default mock for resolveSecret returns an incomplete
ResolvedSecret shape which can cause undefined property access later; update the
vi.fn default in the test so resolveSecret returns the full ResolvedSecret
fields (include scope, allowedHosts, allowedCapabilities, allowedPackages in
addition to found and value) with safe default values (e.g., null/empty
array/empty string as appropriate) so any fallback invocation of resolveSecret
has the complete shape.
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: c22c08e4-0b39-4971-9c81-029af0101cb1
📒 Files selected for processing (1)
packages/worker/src/app/handlers/account-secrets.node.test.ts

Summary
GET /account/secrets.json.Testing
npx vitest run packages/worker/src/app/handlers/account-secrets.node.test.tsnpm run test:e2e:run -- --grep "connect secret shows editable name and scope and saves the edited name"npm run typechecknpm run lint(passes with existing warnings outside this change)Summary by CodeRabbit