Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

feat: mask coder login token to enhance security#12948

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Merged

Conversation

michaelbrewer
Copy link
Contributor

@michaelbrewermichaelbrewer commentedApr 12, 2024
edited
Loading

Masks the coder token when pasting it after thecoder login .

When doing public demos of coder this can be an awkard moment...

MrPeacockNLB reacted with thumbs up emoji
@cdr-botcdr-botbot added the communityPull Requests and issues created by the community. labelApr 12, 2024
@michaelbrewermichaelbrewer changed the titlefeat(login): treat coder token as a secretfeat(login): make coder login token a secretApr 12, 2024
@michaelbrewermichaelbrewer changed the titlefeat(login): make coder login token a secretfeat(login): coder login token as a secretApr 12, 2024
@michaelbrewermichaelbrewer changed the titlefeat(login): coder login token as a secretfeat(login): coder login token should be a secretApr 12, 2024
@michaelbrewermichaelbrewer changed the titlefeat(login): coder login token should be a secretfeat(login): mask coder login token for securityApr 12, 2024
@michaelbrewermichaelbrewer changed the titlefeat(login): mask coder login token for securityfeat: mask coder login token for securityApr 12, 2024
@michaelbrewer
Copy link
ContributorAuthor

@kylecarbs - not sure if i should add some unit tests for this, but i did manually validate that the token still works and is not shown

Copy link
Member

@ericpaulsenericpaulsen left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

in a future state, we should display*** characters, for a better UX.

michaelbrewer reacted with thumbs up emoji
@matifali
Copy link
Member

@ericpaulsen IIRC, it was the original behavior, and the token was shown after some customer feedback.

@coadler
Copy link
Contributor

Yeah, hiding the input was changed because users couldn't tell if they were actually pasting into the box or not. I'm in favor of changing it back to secret until we can add in replacing the text with asterisks.

michaelbrewer reacted with thumbs up emoji

@michaelbrewer
Copy link
ContributorAuthor

@coadler - there are various other places whereSecret is used in a prompt, so i might be a generic solution for those cases too.

coadler reacted with thumbs up emoji

@coadler
Copy link
Contributor

@coadler - there are various other places whereSecret is used in a prompt, so i might be a generic solution for those cases too.

Yeah, definitely.

@michaelbrewer
Copy link
ContributorAuthor

would be nice to have this resolved for when i do demos.

@matifalimatifali requested a review fromsreyaApril 22, 2024 05:45
@michaelbrewermichaelbrewer changed the titlefeat: mask coder login token for securityfeat: mask coder login token to enhance securityApr 27, 2024
@michaelbrewer
Copy link
ContributorAuthor

@ericpaulsen is there a decision on how to handle the secret being printed?

@kylecarbskylecarbs merged commit060f023 intocoder:mainMay 3, 2024
@github-actionsgithub-actionsbot locked and limited conversation to collaboratorsMay 3, 2024
@michaelbrewermichaelbrewer deleted the feat/coder-login-secret branchMay 4, 2024 05:00
Sign up for freeto subscribe to this conversation on GitHub. Already have an account?Sign in.
Reviewers

@kylecarbskylecarbskylecarbs approved these changes

@ericpaulsenericpaulsenericpaulsen approved these changes

@sreyasreyaAwaiting requested review from sreya

Assignees

@michaelbrewermichaelbrewer

Labels
communityPull Requests and issues created by the community.
Projects
None yet
Milestone
No milestone
Development

Successfully merging this pull request may close these issues.

5 participants
@michaelbrewer@matifali@coadler@kylecarbs@ericpaulsen

[8]ページ先頭

©2009-2025 Movatter.jp