- **BREAKING — sync**: `tms.api_key` and `tms.token` are gone from the `.deepl-sync.yaml` schema, leaving `TMS_API_KEY` and `TMS_TOKEN` as the only credential source. Both were accepted with a stderr warning through 1.x and now fail config load with a `ConfigError` (exit 7) that names the environment variable to use instead — `tms.api_key is no longer read from .deepl-sync.yaml` — and never quotes the value. This file is committed, which is its purpose, so a credential written into it was a secret in version control: present in every clone and fork, and surviving its own deletion from the file, so **rotate any credential that has ever been pushed**. Nothing working depended on the file being read, since the environment variable already won wherever both were set. Two consequences reach past the schema. The TMS destination-trust gate loses its bypass: it applied only to environment-supplied credentials, on the reasoning that a credential inlined in the same file that chose the destination leaked nothing of the operator's, and now that every credential comes from the environment, every destination is checked. And `SyncTmsConfig` drops both fields, along with the `'config'` member of the internal credential-provenance type.
0 commit comments