Skip to content

Mask script key in show/list/search output behind --reveal-key - #17

Closed
devin-ai-integration[bot] wants to merge 1 commit into
masterfrom
devin/1790616899-mask-key-in-show
Closed

devin-ai-integration[bot] wants to merge 1 commit into
masterfrom
devin/1790616899-mask-key-in-show

Conversation

@devin-ai-integration

Copy link
Copy Markdown
Contributor

Summary

Follow-up to #14/#15: the fetch log no longer leaks the key, but crmfetch show printed it in its details table, and list --json / search --json dumped it inside the full tenant objects. Same exposure route as the log — scrollback, screenshares, pasted bug reports. Not a real secret boundary (the key sits in plaintext in tenant_settings.json), so this is deliberately opt-out rather than removal:

_hide_key(tenant, reveal_key) -> {**tenant, "key": "*** (use --reveal-key to show)"}  # unless reveal_key or no key

show, list and search each gained a --reveal-key flag; masking applies to both the human-readable and --json forms, so scripts that need the value must ask for it explicitly. --json output is otherwise unchanged (same keys, same shape).

crmfetch add/edit still take the key as an argument, and nothing about the request itself changed.

Tests: python -m pytest tests -q → 90 passed (3 new; the existing show --json test was updated for the intentional behaviour change). readme.md documents neither show nor --json, so nothing to update there.

Link to Devin session: https://app.devin.ai/sessions/6daa0b67c92f45619f580de2a1e3c212
Open in Devin Desktop: https://app.devin.ai/desktop/session/6daa0b67c92f45619f580de2a1e3c212?variant=devin
Requested by: @ehs5

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".

  • Disable automatic comment, CI, and merge conflict monitoring

@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

Closing — filing this as issue #18 instead so it goes through the normal ready-for-agent flow.

@devin-ai-integration
devin-ai-integration Bot deleted the devin/1790616899-mask-key-in-show branch September 28, 2026 17:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant