Skip to content

fix(mothership): show the copy control for API keys created in organization chat - #8861

Merged
waleedlatif1 merged 4 commits into
stagingfrom
fix/secure-copy-reveal
Oct 9, 2026
Merged

waleedlatif1 merged 4 commits into
stagingfrom
fix/secure-copy-reveal

Conversation

@waleedlatif1

@waleedlatif1 waleedlatif1 commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • In organization chat, a workspace API key created by Chat never showed its copy control. The card showed "This credential request needs one explicit workspace target." instead.
  • Cause: the live fill ({value, type}) and the persisted redaction ({type}) each rebuilt the sim_key row from scratch and dropped its workspaceId. Organization chat requires that field on every workspace-targeted credential row. Workspace chat was unaffected, because its check allows a row without a target.
  • Each revealed key is now cached with the workspace its generate_api_key result says it was created in, and the live fill writes that workspace onto the row. The creation result outranks the model's tag, so the chip mounts under the key's real workspace even when the tag omits or misnames it.
  • Redaction keeps the tag's workspaceId only when the renderer would accept it as a target (non-empty, trimmed, at most 256 characters). It still strips the value and any other field, for both the singleton and the array tag forms.
  • CredentialDisplay applies the one-workspace-target rule only to a revealed sim_key. A masked row has nothing to copy and mounts no host, so a saved key renders as the masked chip in any chat, as it did before. Revealed keys still need a valid target in organization chat.

Type of Change

  • Bug fix

Testing

  • Regression at the render boundary (special-tags.test.tsx): a key captured from a generate_api_key result, filled live and rendered on an organization route, now shows the key. The persisted form renders masked with no refusal. Against the old code it fails with the exact refusal text, and reverting either the fill or the redaction change on its own turns it red.
  • special-tags.test.tsx: in a workspace chat, a saved key whose tag names a different workspace renders masked, with no refusal line and no copy button.
  • sim-key-redaction.test.ts:
    • Redaction keeps a valid target and drops untrimmed or overlong ones, along with the value and unknown fields.
    • The fill binds to the creation workspace, and falls back to the tag's workspace when the result carries none.
  • bun run --cwd apps/sim test on lib/mothership/chat and home/: 1025 passed. Root bun run test: everything passed except 2 unrelated load flakes (usage-log, chat-content linearity), which pass when run alone.
  • bun run lint, bun run check:audits, bun run type-check: clean.
  • Independent security review: the key value has no new path to persistence, Slack or the model. A tag's target is still authorized server-side by the workspace host before anything renders.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 9, 2026 9:02pm UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 3 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Turn on auto-fix | Re-trigger cubic

@greptile-apps

greptile-apps Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Medium impact] This PR appears safe to merge; no blocking issues remain.

Summary

This PR restores the copy control for API keys created in organization chat.

  • Organization chat shows new API keys under the workspace where they were created.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart LR
    A[API key creation result] --> B[Live key and workspace]
    B --> C[Workspace check]
    C --> D[Visible key with copy button]
    E[Credential tag] --> F[Remove secret value]
    F --> G[Saved masked key without copy button]
Loading

Reviews (3) · Last reviewed commit: "fix(mothership): render a saved masked k..." · Reviewed by Greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 3 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Turn on auto-fix | Re-trigger cubic

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 4 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Turn on auto-fix | Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit 2ab3211 into staging Oct 9, 2026
47 of 48 checks passed
@waleedlatif1
waleedlatif1 deleted the fix/secure-copy-reveal branch October 9, 2026 22:43

This branch was previously deployed

1 inactive deployment
Preview — 1336b6f4 Deployed Oct 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant