Skip to content

fix(security): protect stored credentials and make API secret fields write-only (#101) - #145

Merged
BerryUIKI merged 1 commit into
devfrom
bugfix/101-protect-stored-credentials
Oct 4, 2026
Merged

BerryUIKI merged 1 commit into
devfrom
bugfix/101-protect-stored-credentials

Conversation

@BerryUIKI

Copy link
Copy Markdown
Owner

Summary

Resolves #101 (F01).

  • Encrypted Local Storage: Uses Windows DPAPI (CryptProtectData / CryptUnprotectData via ctypes) to encrypt credentials stored in credentials.json so raw secrets are never persisted in plaintext. Retains backward compatibility with legacy unencrypted credential files.
  • Surface Persistence Errors: CredentialManager persistence failures raise an actionable OSError and endpoints return HTTP 500 rather than silently claiming success.
  • Secret Redaction: GET /api/v1/agent/llm/config and credential save endpoints return redacted keys (never full secrets).
  • Write-Only Semantics: Updating configuration with a redacted or omitted key preserves the stored key rather than overwriting it.
  • Regression Tests: Added backend/tests/test_credentials_security.py covering encryption, redaction, and write-failure propagation.

Verification

  • pytest backend/tests/test_credentials_security.py: 7/7 passed.
  • Full backend pytest: 164/164 passed.

@BerryUIKI
BerryUIKI merged commit a0f51b9 into dev Oct 4, 2026
3 checks passed
@BerryUIKI
BerryUIKI deleted the bugfix/101-protect-stored-credentials branch October 4, 2026 21:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant