Skip to content

fix(setup): remove nonexistent webhook secret command hint - #1349

Merged
henrypark133 merged 2 commits into
nearai:stagingfrom
G7CNF:codex/issue-1308-webhook-secret-text
Mar 18, 2026
Merged

henrypark133 merged 2 commits into
nearai:stagingfrom
G7CNF:codex/issue-1308-webhook-secret-text

Conversation

@G7CNF

@G7CNF G7CNF commented Mar 18, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Remove the onboarding hint that references a nonexistent ironclaw secret subcommand.
  • Replace it with wording that matches the current behavior: the webhook secret is stored in the encrypted secrets database and loaded automatically on startup.

Validation

  • cargo fmt --all -- --check
  • cargo check -q

Closes #1308

@github-actions github-actions Bot added the scope: setup Onboarding / setup label Mar 18, 2026
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request improves the user onboarding experience by correcting misleading information related to webhook secret management. It removes an obsolete command hint and provides an accurate description of how webhook secrets are stored and utilized, ensuring users receive clear and current guidance during the setup process.

Highlights

  • Onboarding Hint Removal: Removed an outdated onboarding hint that incorrectly referenced a nonexistent ironclaw secret subcommand for retrieving webhook secrets.
  • Webhook Secret Explanation Update: Updated the explanation for webhook secrets to accurately state that they are stored in the encrypted secrets database and loaded automatically on startup.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@github-actions github-actions Bot added size: XS < 10 changed lines (excluding docs) risk: high Safety, secrets, auth, or critical infrastructure contributor: core 20+ merged PRs labels Mar 18, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

The pull request successfully addresses the stated objective of removing a nonexistent command hint and replacing it with accurate information regarding the webhook secret's storage and loading mechanism. The updated message provides clear and correct guidance to the user.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ea4971e67f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/setup/channels.rs Outdated
Comment on lines +521 to +522
print_info(
"The secret is stored in the encrypted secrets database and will be loaded automatically on startup.",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Don't claim startup auto-loads the stored HTTP secret

When users enable the HTTP webhook in the wizard and accept auto-generation, this new message says the saved secret will be loaded on the next start, but the startup path never does that. ChannelsConfig::resolve() still reads the webhook secret only from HTTP_WEBHOOK_SECRET (src/config/channels.rs:99-106), AppBuilder::init_secrets() injects only LLM keys (src/app.rs:230-243), and the DB-backed http_webhook_secret is injected only inside the SIGHUP reload handler (src/main.rs:807-821). On a fresh process, HttpChannel::start() still errors with HTTP webhook secret is required (src/channels/http.rs:651-656), so this guidance leaves the wizard-generated configuration unusable unless the user also exports the secret manually.

Useful? React with 👍 / 👎.

@github-actions github-actions Bot added size: S 10-49 changed lines and removed size: XS < 10 changed lines (excluding docs) labels Mar 18, 2026

@henrypark133 henrypark133 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review: Remove misleading webhook secret command hint

Clean fix. The old ironclaw secret get http_webhook_secret command doesn't exist — this replaces it with an accurate description of the auto-load behavior.

Positives:

  • Extracts hint into http_webhook_secret_hint() for testability
  • Regression test verifies both the new content and absence of the old command
  • Minimal, focused change

LGTM.

@henrypark133
henrypark133 merged commit e9b0823 into nearai:staging Mar 18, 2026
14 checks passed
bkutasi pushed a commit to bkutasi/ironclaw that referenced this pull request Mar 28, 2026
* fix(setup): remove nonexistent webhook secret command hint

* test(setup): cover webhook secret onboarding hint
drchirag1991 pushed a commit to drchirag1991/ironclaw that referenced this pull request Apr 8, 2026
* fix(setup): remove nonexistent webhook secret command hint

* test(setup): cover webhook secret onboarding hint
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: high Safety, secrets, auth, or critical infrastructure scope: setup Onboarding / setup size: S 10-49 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

"ironclaw secret" is not a valid command, http webhook setup fails

2 participants