Skip to content

fix(web): keep the stored value when a secret edit leaves it blank - #18

Merged
sirsjg merged 1 commit into
mainfrom
fix/secret-metadata-edit
Sep 9, 2026
Merged

sirsjg merged 1 commit into
mainfrom
fix/secret-metadata-edit

Conversation

@sirsjg

@sirsjg sirsjg commented Sep 9, 2026

Copy link
Copy Markdown
Owner

What

Editing a secret to change only its note or tags forced you to re-enter a replacement value, and the value field claimed plaintext is "never shown after save" — which the reveal control disproves.

  • PATCH /api/v1/secrets/:secretId no longer requires value. Without one, SecretService.update edits notes and tags in place: no new secret_versions row, and no environment config_version bump, so runtime consumers are not forced to re-fetch for a note change. A changeNote sent without a value is rejected as INVALID_INPUT rather than silently dropped.
  • The editor's value field is optional in edit mode ("New value · optional"), explains that blank keeps the current value, hides the change note until a value is typed, and submits as Save changes instead of Create new version. A blank value also no longer bumps the optimistic version or re-masks a revealed row.
  • The inaccurate "never shown after save" placeholder is gone.

Also lands the consistency-panel work that was pending in the working tree: the cross-environment diff collapses behind Show details, and cellFindings stops badging the environments that hold a key as missing it.

Tests

  • New Postgres test: a note-only update keeps the value and version and writes no version row; a change note without a value is rejected.
  • New client assertion: a details-only edit sends no value.
  • New e2e steps: note-only edit saves, the row stays on v1, and the change-note field is absent. E2E fixtures now model secret rows and serve the secret PATCH.
  • Unit + e2e (9), typecheck, and docs:check pass locally. docs/openapi.json regenerated. The Postgres suites could not run locally (no Postgres or Docker on this machine) — CI covers them.

🤖 Generated with Claude Code

https://claude.ai/code/session_01N3xGYJfHiv11Snq9p98Z4Q

Updating a secret demanded a replacement value even when only the note or
tags were changing, and the value field promised plaintext is "never shown
after save" — which the reveal control disproves.

- PATCH /api/v1/secrets/:secretId no longer requires `value`. Without one,
  SecretService edits notes and tags in place: no new secret version, no
  environment config-version bump, so runtime clients are not forced to
  re-fetch for a note. A change note sent without a value is rejected
  rather than silently dropped.
- The editor's value field is optional in edit mode, explains that blank
  keeps the current value, hides the change note until a value is typed,
  and submits as "Save changes" instead of "Create new version".
- Drops the inaccurate "never shown after save" placeholder.

Also lands the consistency-panel work that was pending in the working
tree: the cross-environment diff collapses behind "Show details", and
cellFindings stops badging the environments that hold a key as missing it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N3xGYJfHiv11Snq9p98Z4Q
@sirsjg
sirsjg merged commit 6df08b8 into main Sep 9, 2026
9 checks passed
@sirsjg
sirsjg deleted the fix/secret-metadata-edit branch September 9, 2026 05:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant