fix(codegen/digitalocean): mark secret-named spec fields sensitive (swamp-club #3030) #455
Loading…
Reference in a new issue
No description provided.
Delete branch "issue-3030"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
The generated
@swamp/digitaloceanmodels carried real secrets as plainz.string(): database connection passwords, App Platform log destination credentials, registry credentials and API keys. Only the injected top-leveltokenargument was marked sensitive. A dry-runswamp extension pushreported 227 Credentials & Secrets warnings.Change
codegen/digitalocean/extensionModelGenerator.tsmarks a field with.meta({ sensitive: true })when its name is, or ends in_plus, one ofpassword,secret,token,api_key,access_key,private_key,registry_credentials. It applies to plain strings and property-less objects, in GlobalArgsSchema, InputsSchema, ResourceSchema and action and sub-resource arguments.access_keyID stays a plain value.2026.10.05.1. Nothing undermodel/is hand-edited.codegen/designs/digitalocean.md, a Secret fields section in the generated README, and a one-sentence correction incodegen/designs/vercel.md.Behavior change for users
insight_notification_channel,monitoring_sink,action_gateway_connection) now need a configured vault to save state. Swamp rejects their non-read methods up front when none exists.vault.get(...)expression.Known gaps
app_platformandapp_deployment) carry the meta but are not vaulted yet: swamp-club #3038.connection.urion the database models still contains the password in plaintext, andslack.webhook_urlandauth_keyare not matched by the name rule. Raised by the adversarial review; left for a follow-up.security_secret.tsis an orphaned file the generator no longer produces: swamp-club #3041.Verification
access_keyID.2e9514b93.🤖 Generated with Claude Code
The generator only marked the injected top-level token argument. Spec fields holding real secrets (database connection passwords, App Platform log destination credentials, registry credentials, API keys) were plain strings. A field whose name is, or ends in an underscore plus, password, secret, token, api_key, access_key, private_key or registry_credentials now gets .meta({ sensitive: true }) in GlobalArgsSchema, InputsSchema, ResourceSchema and action and sub-resource arguments. Regenerated @swamp/digitalocean: 215 fields in 14 models. Models that read secrets back from the API now need a vault to save state, and literal secrets in definitions are rejected. Fields nested under arrays carry the meta but are not vaulted by swamp core yet (swamp-club #3038). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>