Skip to content

fix(storage): secrets can be removed on edit, SSH secrets go with the tunnel, a failed save restores them all (#1311) - #1330

Merged
ZhuchkaTriplesix merged 2 commits into
devfrom
fix/1311-secret-clearing
Oct 10, 2026
Merged

ZhuchkaTriplesix merged 2 commits into
devfrom
fix/1311-secret-clearing

Conversation

@ZhuchkaTriplesix

Copy link
Copy Markdown
Member

Closes #1311

Problem

  1. The edit form never shows saved secrets and treats a blank field as keep the saved one, so a saved password could not be removed (the database moved to trust authentication, or it must not stay on disk).
  2. writeForConnection wrote SSH secrets only when one was non-null: turning the tunnel off left its password, private key and passphrase in the keyring until the connection was deleted.
  3. When writing secrets failed, updateConnection restored the row and the password / connection string but not the SSH secrets, which are written key by key and may be half replaced.

Fix

  • ConnectionRow.removeSavedPassword (never stored). PostgreSQL, MySQL, MongoDB and Redis edit forms get a Remove the saved password checkbox (edit mode only; it disables the field). mergeSecretsForConnectionUpdate drops the saved password for it (a password typed with the request still replaces); Test Connection then tests without the saved one.
  • updateConnection clears the four SSH secrets when the saved row has no enabled tunnel and brings none.
  • updateConnection snapshots the SSH secrets with the other ones and restores all of them when a write fails.
  • Not changed: clearing only some SSH fields is still done by replacing them; a blank SSH field keeps the saved one.

Tests (local_db_secrets_test.dart): a blank field keeps, the request removes (and the store really loses it), a typed password with the request replaces; a connection saved without a tunnel has no SSH secret left; a write failing on the fourth key restores the previous SSH password and key (with a backend that fails on the Nth write).

… tunnel, a failed save restores them all (#1311)

- An edit form has Remove the saved password; a blank field still keeps
  it. Test Connection honours it.
- Saving a connection without a tunnel removes its SSH password, key and
  passphrase from the keyring instead of leaving them there.
- A failed secret write restores the SSH secrets too (they are written
  key by key), not only the password and connection string.
@github-actions github-actions Bot added bug Something isn't working storage Theme parser epic label: storage connections Database connections, URI parsing, pools P2 Medium priority / Parity & Refactoring labels Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working connections Database connections, URI parsing, pools P2 Medium priority / Parity & Refactoring storage Theme parser epic label: storage

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant