Problem
lib/features/connections/connection_edit_secrets.dart, lib/core/storage/connection_secrets_store.dart, lib/core/storage/local_db.dart (updateConnection):
- No way to clear. A blank password / SSH field means keep the previous one, and the form never shows the stored value, so a saved password cannot be removed (the database moved to trust authentication, the SSH key is gone).
- Stale SSH secrets.
writeForConnection writes SSH secrets only when one of them is non-null. Turning SSH off leaves the old password, private key and passphrase in the keyring until the connection is deleted.
- Partial rollback. When writing secrets fails,
updateConnection restores the previous row and the password / connection string, but not the SSH secrets, which may already be partly overwritten (writeSshSecretsForConnection writes four keys one by one).
writeSshSecretsForConnection writes all four keys: a caller that passes only one nulls the other three.
Scope
- An explicit Remove saved password / Remove saved SSH secrets action in the forms (a tri-state: keep / replace / clear).
- Delete SSH secrets when the tunnel is disabled.
- Snapshot and restore all secrets (database and SSH) on a failed update.
- Tests with a fake backend: clear, disable SSH, failing write mid-way.
Acceptance
Problem
lib/features/connections/connection_edit_secrets.dart,lib/core/storage/connection_secrets_store.dart,lib/core/storage/local_db.dart(updateConnection):writeForConnectionwrites SSH secrets only when one of them is non-null. Turning SSH off leaves the old password, private key and passphrase in the keyring until the connection is deleted.updateConnectionrestores the previous row and the password / connection string, but not the SSH secrets, which may already be partly overwritten (writeSshSecretsForConnectionwrites four keys one by one).writeSshSecretsForConnectionwrites all four keys: a caller that passes only one nulls the other three.Scope
Acceptance