Skip to content

Connectors: Keep a stored API key read-only when it can't be verified - #83889

Merged
jorgefilipecosta merged 1 commit into
trunkfrom
fix/connectors-read-only-stored-api-key
Oct 1, 2026
Merged

jorgefilipecosta merged 1 commit into
trunkfrom
fix/connectors-read-only-stored-api-key

Conversation

@jorgefilipecosta

@jorgefilipecosta jorgefilipecosta commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Related to https://core.trac.wordpress.org/ticket/65551 and WordPress/wordpress-develop#13870.

Currently, the API key field on the Connectors screen is only read-only while the connector shows as connected. When a stored key can't be verified, for example while the provider is unreachable, the connector shows as not connected, and the field is editable and pre-filled with the masked key the settings endpoint returns. Saving it overwrites the stored key and makes it invating.

To fix this, a stored key is now always shown read-only, as for a connected provider, so it has to be removed with "Remove and replace" before entering a new one. The settings form now remounts when it switches between read-only and editable, so the field is empty after the key is removed.

Testing Instructions

  1. On Settings > Connectors, install and activate the OpenAI provider.
  2. Store a key.
  3. Reload the page and verify it says connected.
  4. Disconnect the internet from the test env (turninoff wi-fi ethernet on a dev machine does the trick).
  5. Reload the page and verify it does not says connected, open the setup and verify the key is not editable to set a new key one needs to remove the first key. On trunk the key is editable and sabable which would allow users to just discard a valid ket during outage.
  6. Run npm run test:unit -- routes/connectors-home.

AI usage disclosure: fix and description drafted with AI assistance and reviewed by me.

@jorgefilipecosta jorgefilipecosta added [Type] Bug An existing feature does not function as intended [Feature] Connectors screen Tracks connectors screen related tasks labels Sep 30, 2026
jorgefilipecosta added a commit to jorgefilipecosta/wordpress-develop that referenced this pull request Sep 30, 2026
The Connectors screen no longer submits a masked API key, as it shows a
stored key read-only until it is removed, so the setting does not need
to handle one: WordPress/gutenberg#83889

See #65551.
@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

🤖 PR meta 🤖

🎉 Props

If you're merging code through a pull request on GitHub, copy and paste the following into the bottom of the merge commit message.

Co-authored-by: jorgefilipecosta <[email protected]>

To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook.

Updated as activity occurs, without notifying anyone named here. Add the props-bot label to refresh.

📦 Bundle size

Size Change: 0 B

Total Size: 8.25 MB

7ead448 Run

⚡ Performance

Show the results

Client side metrics exclude the server response time.

front-end-block-theme

Metric 4f61acf trunk % Change
timeToFirstByte 57.95 ms +10.7% -3.71% 58.9 ms +7.81% -3.4% -1.61%
largestContentfulPaint 100 ms +8% -8% 98 ms +6.12% -4.08% 2.04%
lcpMinusTtfb 42.05 ms +5.35% -15.58% 36 ms +20.69% -3.19% 16.81%
wpBeforeTemplate 29.07 ms +14.24% -2.03% 29.04 ms +14.22% -2.03% 0.1%
wpTemplate 24.65 ms +3.61% -3.85% 25.14 ms +4.73% -2.11% -1.95%
wpTotal 54.14 ms +10.47% -3.75% 55.27 ms +7.65% -3.98% -2.04%
wpMemoryUsage 7.62 MB +0% -0% 7.59 MB +0% -0% 0.46%
wpDbQueries 17 +0% -0% 17 +0% -0% 0%

front-end-classic-theme

Metric 4f61acf trunk % Change
timeToFirstByte 43.95 ms +8.99% -2.62% 49.25 ms +5.79% -1.93% -10.76%
largestContentfulPaint 92 ms +4.35% -0% 108 ms +0% -3.7% -14.81%
lcpMinusTtfb 49 ms +0.41% -3.47% 56.25 ms +2.58% -1.87% -12.89%
wpBeforeTemplate 27.19 ms +11.4% -2.91% 27.1 ms +13.69% -1.62% 0.33%
wpTemplate 13.95 ms +3.01% -2.15% 18.69 ms +3.91% -1.71% -25.36%
wpTotal 41.25 ms +9.31% -3.18% 46.1 ms +5.84% -1.8% -10.52%
wpMemoryUsage 6.11 MB +0% -0% 6.20 MB +0% -0% -1.57%
wpDbQueries 10 +0% -0% 14 +0% -0% -28.57%

media-processing

Metric 4f61acf trunk % Change
mediaProcessingJpeg 401.85 ms +1.66% -0.18% 402.49 ms +0.17% -1.6% -0.16%
mediaProcessingAvif 6069.54 ms +0.51% -0.14% 6067.76 ms +0.03% -0.25% 0.03%
mediaProcessingJpegToAvif 4186.34 ms +0.31% -0.08% 4186.91 ms +0.43% -0.17% -0.01%

media-upload

Metric 4f61acf trunk % Change
jpegUploadProcessing 1449.66 ms +35.53% -0.89% 1418.96 ms +1.35% -0.41% 2.16%
pngUploadProcessing 201.2 ms +10.36% -9% 196.08 ms +13.34% -7.69% 2.61%
largeJpegUploadProcessing 1424.43 ms +0.37% -1.38% 1407.97 ms +0.63% -0.42% 1.17%
multipleImageUploadProcessing 1608.58 ms +8.89% -1.7% 1581.67 ms +8.47% -0.35% 1.7%

post-editor

Metric 4f61acf trunk % Change
serverResponse 316 ms +3.05% -0.65% 339.85 ms +2.74% -5.54% -7.02%
firstPaint 173.48 ms +35.66% -17.23% 198.06 ms +10.74% -24.12% -12.41%
domContentLoaded 839.55 ms +2.07% -1.89% 840.57 ms +0.54% -0.48% -0.12%
loaded 840.6 ms +2.07% -1.88% 841.47 ms +0.55% -0.49% -0.1%
firstContentfulPaint 360.64 ms +3.14% -2.04% 359.26 ms +1.73% -1.46% 0.38%
firstBlock 2429.9 ms +2.91% -0.42% 2404.54 ms +0.81% -0.26% 1.05%
type 15.8 ms +2.41% -5.7% 15.78 ms +1.71% -1.52% 0.13%
typeWithoutInspector 15.13 ms +3.97% -2.97% 15.57 ms +1.22% -3.66% -2.83%
typeWithTopToolbar 19.83 ms +2.57% -1.56% 19.92 ms +1.91% -4.17% -0.45%
typeContainer 7.52 ms +7.58% -7.05% 7.55 ms +1.46% -2.52% -0.4%
focus 58.68 ms +17.88% -2.57% 57.52 ms +8.24% -4.89% 2.02%
firstFocus 151.74 ms +0% -0% 155.09 ms +0% -0% -2.16%
selectAll 357.44 ms +4.36% -1.15% 338.23 ms +6.03% -3.33% 5.68%
listViewOpen 48.8 ms +5.35% -2.91% 49.07 ms +6.52% -2.14% -0.55%
inserterOpen 18.55 ms +20.05% -4.69% 19.77 ms +17.2% -8.55% -6.17%
inserterHover 1.85 ms +12.43% -12.97% 1.86 ms +6.99% -8.6% -0.54%
inserterSearch 7.28 ms +2.61% -3.71% 7.31 ms +8.34% -3.69% -0.41%
loadPatterns 517.43 ms +2.61% -2.29% 520.2 ms +1.56% -3.94% -0.53%
wpTotal 307.51 ms +3.03% -0.65% 331.43 ms +2.83% -5.73% -7.22%
wpMemoryUsage 13.17 MB +0% -0% 13.13 MB +0% -0% 0.25%
wpDbQueries 54 +0% -0% 54 +0% -0% 0%

site-editor

Metric 4f61acf trunk % Change
serverResponse 338.77 ms +7% -4.9% 338.51 ms +6.45% -2.51% 0.08%
firstPaint 196.25 ms +2.41% -21% 222.81 ms +62.95% -23.22% -11.92%
domContentLoaded 911.59 ms +1.37% -1.18% 896.86 ms +2.12% -4.22% 1.64%
loaded 912.53 ms +1.37% -1.17% 897.73 ms +2.14% -4.2% 1.65%
firstContentfulPaint 375.07 ms +1.95% -1.1% 369.8 ms +1.25% -1.82% 1.43%
firstBlock 3178.82 ms +0.98% -0.23% 3203.63 ms +1.01% -0.52% -0.77%
type 15.76 ms +4.06% -2.28% 15.69 ms +7.52% -4.02% 0.45%
navigate 99.79 ms +5.72% -2.43% 112.27 ms +1.05% -6.64% -11.12%
loadPatterns 1045.45 ms +12.51% -1.98% 1088.85 ms +8.43% -2.74% -3.99%
loadPages 1120.65 ms +2.21% -2.6% 1126.79 ms +1.91% -11.37% -0.54%
wpTotal 330.16 ms +7.15% -4.91% 329.88 ms +6.63% -2.53% 0.08%
wpMemoryUsage 12.14 MB +0% -0% 12.11 MB +0% -0% 0.3%
wpDbQueries 43.5 +1.15% -1.15% 44 +0% -2.27% -1.14%

7ead448 Run

🏁 Flaky tests

Some tests passed with failed attempts. The failures may not be related to this commit but are still reported for visibility. See the documentation for more information.

sort patterns (Site Editor v2) in /test/e2e/specs/site-editor/patterns.spec.js, passed after 1 failed attempt.
Error: apiRequestContext.fetch: socket hang up
Call log:
  - → POST http://localhost:8889/wp-json/wp/v2/blocks
    - user-agent: Playwright/1.63.0 (x64; ubuntu 24.04) node/24.18 CI/1
    - accept: */*
    - accept-encoding: gzip,deflate,br
    - X-WP-Nonce: 00e553ac5a
    - content-type: application/json
    - content-length: 133
    - cookie: wordpress_test_cookie=WP%20Cookie%20check; wordpress_logged_in_23778236db82f19306f247e20a353a99=admin%7C1791029431%7CMt9ViqUD2vp3Cx0egud0vTbu8Z1PQGwEpxLt3fu9qVs%7Cf011c8f451d377f86705e656176f3431d4a1863e84d5d2f826969c5dcecaa819; wp-settings-time-1=1790856932

    at RequestUtils.rest (/home/runner/work/gutenberg/gutenberg/packages/e2e-test-utils-playwright/src/request-utils/rest.ts:112:39)
    at RequestUtils.createRecord (/home/runner/work/gutenberg/gutenberg/packages/e2e-test-utils-playwright/src/request-utils/records.ts:20:14)
    at RequestUtils.createBlock (/home/runner/work/gutenberg/gutenberg/packages/e2e-test-utils-playwright/src/request-utils/blocks.ts:54:14)
    at /home/runner/work/gutenberg/gutenberg/test/e2e/specs/site-editor/patterns.spec.js:241:17

7ead448 Run

The settings endpoint only returns stored API keys masked. When a stored
key could not be verified, for example while the provider was
unreachable, the settings form was editable and pre-filled with the
mask, so saving it overwrote the stored key. Show a stored key read-only,
as for a connected provider, so it has to be removed before entering a
new one.
@jorgefilipecosta
jorgefilipecosta force-pushed the fix/connectors-read-only-stored-api-key branch from 10cb3f9 to 7ead448 Compare October 1, 2026 12:05
@jorgefilipecosta
jorgefilipecosta merged commit 57d46c0 into trunk Oct 1, 2026
77 checks passed
@jorgefilipecosta
jorgefilipecosta deleted the fix/connectors-read-only-stored-api-key branch October 1, 2026 15:09
@github-actions github-actions Bot added this to the Gutenberg 24.2 milestone Oct 1, 2026
widoz pushed a commit to widoz/gutenberg that referenced this pull request Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

[Feature] Connectors screen Tracks connectors screen related tasks [Type] Bug An existing feature does not function as intended

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant