Skip to content

chore(status): bt status prints which secret storage is used - #341

Open
Cedric / ViaDézo1er (viadezo1er) wants to merge 1 commit into
mainfrom
cedric/clarify-credential-metadata-vs-secret-storage
Open

chore(status): bt status prints which secret storage is used#341
Cedric / ViaDézo1er (viadezo1er) wants to merge 1 commit into
mainfrom
cedric/clarify-credential-metadata-vs-secret-storage

Conversation

@viadezo1er

@viadezo1er Cedric / ViaDézo1er (viadezo1er) commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

clarifies that config.json is metadata and not secrets

Read the description of #344, this PR might need tweaking to better support Windows.

Before:

✓ cedric — https://www.braintrust.dev — oauth — api: https://api.braintrust.dev — Cedric Halber (cedric@braintrustdata.com)
✓ cedric-2 — http://localhost:3000 — oauth — api: http://localhost:8000 — Cédric Halber (cedric@braintrustdata.com)
✓ profile — https://www.braintrust.dev — api_key — bt-****vVjh3

Credentials: /Users/cedric@braintrustdata.com/.config/bt/auth.json

org: ced
project: My Project
project_id: 8bd69204-1f16-4eef-b8ce-74f20bede6f7
profile: cedric-2
app_url: http://localhost:3000
api_url: http://localhost:8000
auth: oauth — Cédric Halber (cedric@braintrustdata.com)
source: /Users/cedric@braintrustdata.com/.bt/config.json

After:

✓ cedric — https://www.braintrust.dev — oauth — api: https://api.braintrust.dev — Cedric Halber (cedric@braintrustdata.com)
✓ cedric-2 — http://localhost:3000 — oauth — api: http://localhost:8000 — Cédric Halber (cedric@braintrustdata.com)
✓ profile — https://www.braintrust.dev — api_key — bt-****vVjh3

Secret storage: macOS Keychain
Profile metadata: /Users/cedric@braintrustdata.com/.config/bt/auth.json

org: ced
project: My Project
project_id: e52400bc-f0f5-4d60-81ce-c1dd7aa933d1
profile: cedric-2
app_url: http://localhost:3000
api_url: http://localhost:8000
auth: oauth — Cédric Halber (cedric@braintrustdata.com)
source: /Users/cedric@braintrustdata.com/.config/bt/config.json

clarifies that config.json is metadata and not secrets
@github-actions

Copy link
Copy Markdown
Contributor

Latest downloadable build artifacts for this PR commit ef6de491efd7:

Available artifact names
  • artifacts-build-global
  • artifacts-build-local-x86_64-apple-darwin
  • artifacts-build-local-x86_64-pc-windows-msvc
  • artifacts-build-local-aarch64-pc-windows-msvc
  • artifacts-build-local-aarch64-apple-darwin
  • artifacts-build-local-x86_64-unknown-linux-musl
  • artifacts-build-local-x86_64-unknown-linux-gnu
  • artifacts-build-local-aarch64-unknown-linux-gnu
  • artifacts-plan-dist-manifest
  • cargo-dist-cache

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ef6de491ef

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "Codex (@codex) review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "Codex (@codex) address that feedback".

Comment thread src/auth.rs
Comment on lines +2185 to +2187
SecretStorageInfo {
backend: SECURE_STORAGE_BACKEND.expect("secure storage backend checked above"),
path: None,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Verify the secure backend before reporting it

On Linux or macOS, when the secure-store utility or service is unavailable and secrets.json is absent or empty, this branch reports the platform secure backend solely from the compile target. For example, a Linux installation without secret-tool can show Linux Secret Service (via secret-tool) even while profile verification reports a missing credential and any subsequent save would fall back to plaintext. Probe backend availability or report that no active backend was detected instead of claiming the secure backend is in use.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant