Skip to content

fix(setup): initialize secrets_crypto for env var mode in setup wizard - #669

Closed
ezhoureal wants to merge 2 commits into
nearai:mainfrom
ezhoureal:fix/setup-wizard-env-var-secrets-crypto
Closed

ezhoureal wants to merge 2 commits into
nearai:mainfrom
ezhoureal:fix/setup-wizard-env-var-secrets-crypto

Conversation

@ezhoureal

Copy link
Copy Markdown
Contributor

When users chose "Environment variable" option in Step 2 (Security) of the setup wizard, the secrets_crypto context was not initialized. This caused API key saves in Step 3 (LLM Provider) to fail silently, leaving users with no stored API key and a non-working LLM configuration.

Changes:

  • Add secrets_master_key_hex field to SetupWizard to store the generated key
  • Initialize secrets_crypto when env var mode is chosen (like keychain mode)
  • Write SECRETS_MASTER_KEY to ~/.ironclaw/.env automatically via write_bootstrap_env
  • Update wizard message to inform users the key will be written automatically
  • Add regression tests for issue Setup wizard: OpenAI-compatible model config doesn't save API key #666

Fixes #666

When users chose "Environment variable" option in Step 2 (Security) of
the setup wizard, the secrets_crypto context was not initialized. This
caused API key saves in Step 3 (LLM Provider) to fail silently, leaving
users with no stored API key and a non-working LLM configuration.

Changes:
- Add secrets_master_key_hex field to SetupWizard to store the generated key
- Initialize secrets_crypto when env var mode is chosen (like keychain mode)
- Write SECRETS_MASTER_KEY to ~/.ironclaw/.env automatically via write_bootstrap_env
- Update wizard message to inform users the key will be written automatically
- Add regression tests for issue #666

Fixes #666

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Tianer Zhou <ezhoureal@gmail.com>
@github-actions github-actions Bot added scope: setup Onboarding / setup size: M 50-199 changed lines risk: high Safety, secrets, auth, or critical infrastructure contributor: new First-time contributor labels Mar 7, 2026
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request resolves a critical bug in the setup wizard where API keys failed to save silently when the "Environment variable" security option was chosen. The changes ensure that the necessary cryptographic context is initialized, the generated master key is persisted correctly, and the user is informed of the automatic key saving process, leading to a robust and functional LLM configuration.

Highlights

  • Secrets Initialization: The secrets_crypto context is now properly initialized when users select the "Environment variable" option for secrets management in the setup wizard, resolving a silent failure in API key storage.
  • Master Key Storage and Persistence: A new secrets_master_key_hex field was added to the SetupWizard to store the generated master key, which is then automatically written to the ~/.ironclaw/.env file via write_bootstrap_env.
  • User Experience: Wizard messages have been updated to inform users that the master key will be automatically written to their .env file.
  • Test Coverage: New regression tests were added to cover the scenario where the environment variable mode is chosen, ensuring secrets_crypto is initialized and the master key is correctly stored and written.
Changelog
  • src/setup/wizard.rs
    • Added a new secrets_master_key_hex field to the SetupWizard struct to store the generated master key.
    • Initialized the secrets_master_key_hex field to None in the SetupWizard constructors.
    • Modified the step_security method to initialize secrets_crypto and store the generated master key when the environment variable mode is selected.
    • Updated the console output messages in step_security to reflect the automatic writing of the master key to the .env file.
    • Extended the write_bootstrap_env method to include the SECRETS_MASTER_KEY in the generated .env file if it has been set.
    • Introduced two new regression tests to verify the correct initialization of the secrets_master_key_hex field and its inclusion in the bootstrap environment file.
Activity
  • No human activity has been recorded on this pull request yet.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request effectively addresses a critical bug in the setup wizard where the secrets crypto context was not being initialized for the environment variable mode. The changes are logical, and the inclusion of regression tests is a great addition to prevent this issue from recurring. I've identified one high-severity issue in the new tests related to test isolation, which could lead to flakiness due to shared global state, and have provided a detailed suggestion for resolution, referencing relevant testing guidelines.

Note: Security Review did not run due to the size of the PR.

Comment thread src/setup/wizard.rs
Use a temporary directory with IRONCLAW_BASE_DIR env var instead of
writing to the user's actual ~/.ironclaw/.env file. This prevents
side effects and makes the test isolated and reliable.

Co-Authored-By: Claude <noreply@anthropic.com>

@zmanian zmanian left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The fix addresses a real bug (issue #666) -- env var mode left secrets_crypto uninitialized, causing silent failures in subsequent wizard steps. The approach is correct.

Three issues:

  1. Use SecretString for secrets_master_key_hex -- The master encryption key is stored as a plain String that won't be zeroed on drop. The project uses secrecy::SecretString extensively (e.g., llm_api_key: Option<SecretString> on the same struct). The master key should be Option<SecretString>.

  2. Missing inject_single_var call -- After generating the key, SECRETS_MASTER_KEY won't be visible to optional_env() during the rest of the wizard session until the process restarts and reads the .env file. Need crate::config::inject_single_var("SECRETS_MASTER_KEY", &key_hex).

  3. First test is a tautology -- test_secrets_master_key_hex_field_initialized manually sets fields then asserts they're Some. It doesn't exercise any real code path. Consider testing that the crypto context can actually encrypt/decrypt with the generated key. The second test (bootstrap env) is good.

@ezhoureal ezhoureal closed this Mar 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: new First-time contributor risk: high Safety, secrets, auth, or critical infrastructure scope: setup Onboarding / setup size: M 50-199 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Setup wizard: OpenAI-compatible model config doesn't save API key

2 participants