fix(codegen/digitalocean): mark secret-named spec fields sensitive (swamp-club #3030) #455

Merged
zacharyhamm merged 3 commits from issue-3030 into main 2026-10-05 20:01:15 +00:00
Owner

Problem

The generated @swamp/digitalocean models carried real secrets as plain z.string(): database connection passwords, App Platform log destination credentials, registry credentials and API keys. Only the injected top-level token argument was marked sensitive. A dry-run swamp extension push reported 227 Credentials & Secrets warnings.

Change

  • codegen/digitalocean/extensionModelGenerator.ts marks a field with .meta({ sensitive: true }) when its name is, or ends in _ plus, one of password, secret, token, api_key, access_key, private_key, registry_credentials. It applies to plain strings and property-less objects, in GlobalArgsSchema, InputsSchema, ResourceSchema and action and sub-resource arguments.
  • The resource's identifying field is never marked, compared with underscores ignored, so the public Spaces access_key ID stays a plain value.
  • Regenerated models: 214 fields in 13 model files, version 2026.10.05.1. Nothing under model/ is hand-edited.
  • Docs: a Sensitive fields section in codegen/designs/digitalocean.md, a Secret fields section in the generated README, and a one-sentence correction in codegen/designs/vercel.md.

Behavior change for users

  • Models that read secrets back from the API (the database models, insight_notification_channel, monitoring_sink, action_gateway_connection) now need a configured vault to save state. Swamp rejects their non-read methods up front when none exists.
  • A literal value in a sensitive global argument is rejected when the definition is saved; use a vault.get(...) expression.

Known gaps

  • Swamp core only acts on sensitive fields reached through plain objects. Fields under arrays (most of app_platform and app_deployment) carry the meta but are not vaulted yet: swamp-club #3038.
  • connection.uri on the database models still contains the password in plaintext, and slack.webhook_url and auth_key are not matched by the name rule. Raised by the adversarial review; left for a follow-up.
  • security_secret.ts is an orphaned file the generator no longer produces: swamp-club #3041.

Verification

  • Dry-run push: Credentials & Secrets warnings 227 → 13. Twelve are substring matches on non-secret names owned by swamp-club #3019; one is the Spaces access_key ID.
  • verify-build 11/11 and verify-reviews (code review and adversarial review pass, ci-security-review skipped by its guard). Attestation posted for 2e9514b93.
  • Generation run twice with an identical diff.

🤖 Generated with Claude Code

## Problem The generated `@swamp/digitalocean` models carried real secrets as plain `z.string()`: database connection passwords, App Platform log destination credentials, registry credentials and API keys. Only the injected top-level `token` argument was marked sensitive. A dry-run `swamp extension push` reported 227 Credentials & Secrets warnings. ## Change - `codegen/digitalocean/extensionModelGenerator.ts` marks a field with `.meta({ sensitive: true })` when its name is, or ends in `_` plus, one of `password`, `secret`, `token`, `api_key`, `access_key`, `private_key`, `registry_credentials`. It applies to plain strings and property-less objects, in GlobalArgsSchema, InputsSchema, ResourceSchema and action and sub-resource arguments. - The resource's identifying field is never marked, compared with underscores ignored, so the public Spaces `access_key` ID stays a plain value. - Regenerated models: 214 fields in 13 model files, version `2026.10.05.1`. Nothing under `model/` is hand-edited. - Docs: a Sensitive fields section in `codegen/designs/digitalocean.md`, a Secret fields section in the generated README, and a one-sentence correction in `codegen/designs/vercel.md`. ## Behavior change for users - Models that read secrets back from the API (the database models, `insight_notification_channel`, `monitoring_sink`, `action_gateway_connection`) now need a configured vault to save state. Swamp rejects their non-read methods up front when none exists. - A literal value in a sensitive global argument is rejected when the definition is saved; use a `vault.get(...)` expression. ## Known gaps - Swamp core only acts on sensitive fields reached through plain objects. Fields under arrays (most of `app_platform` and `app_deployment`) carry the meta but are not vaulted yet: swamp-club #3038. - `connection.uri` on the database models still contains the password in plaintext, and `slack.webhook_url` and `auth_key` are not matched by the name rule. Raised by the adversarial review; left for a follow-up. - `security_secret.ts` is an orphaned file the generator no longer produces: swamp-club #3041. ## Verification - Dry-run push: Credentials & Secrets warnings 227 → 13. Twelve are substring matches on non-secret names owned by swamp-club #3019; one is the Spaces `access_key` ID. - verify-build 11/11 and verify-reviews (code review and adversarial review pass, ci-security-review skipped by its guard). Attestation posted for `2e9514b93`. - Generation run twice with an identical diff. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
The generator only marked the injected top-level token argument. Spec fields
holding real secrets (database connection passwords, App Platform log
destination credentials, registry credentials, API keys) were plain strings.

A field whose name is, or ends in an underscore plus, password, secret, token,
api_key, access_key, private_key or registry_credentials now gets
.meta({ sensitive: true }) in GlobalArgsSchema, InputsSchema, ResourceSchema
and action and sub-resource arguments. Regenerated @swamp/digitalocean: 215
fields in 14 models.

Models that read secrets back from the API now need a vault to save state, and
literal secrets in definitions are rejected. Fields nested under arrays carry
the meta but are not vaulted by swamp core yet (swamp-club #3038).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
update and sync read the identifying field back from stored state to build API
paths, so it must stay a plain value even when its name looks like a secret.
Also restores the doc comment on generateRegionZod and scopes the action and
sub-resource argument test to its own method blocks.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
fix(codegen/digitalocean): keep the Spaces access key ID unmarked (swamp-club #3030)
All checks were successful
CI / Validate Attestation (pull_request) Successful in 1m14s
CI / Review Integrity (pull_request) Successful in 1m20s
2e9514b936
The identifying-field exemption now also matches when the property name equals
the identifying field with underscores removed, because the pipeline's
identifier fallback strips them (accesskey for access_key). space_key is
unchanged from main; 214 fields in 13 models are marked.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign in to join this conversation.
No reviewers
No labels
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
swamp-club/swamp-extensions!455
No description provided.