Skip to content

fix(security): never persist the OAuth access token (v0.1.2) - #3

Merged
TheStreamCode merged 1 commit into
mainfrom
fix/credential-hygiene
Sep 27, 2026
Merged

TheStreamCode merged 1 commit into
mainfrom
fix/credential-hygiene

Conversation

@TheStreamCode

Copy link
Copy Markdown
Owner

writeCache sanitizes at the sink: only apiKey/accountId/email touch disk. Test asserts oauthAccessToken absence from the raw file. README documents stored fields. Verified locally: build + 7 node tests green.

writeCache now persists only apiKey/accountId/email; the OAuth token stays in memory (nothing ever read it back). Test asserts absence from the raw cache file. README documents the stored fields.
@TheStreamCode
TheStreamCode merged commit 26b9332 into main Sep 27, 2026
4 checks passed
@TheStreamCode
TheStreamCode deleted the fix/credential-hygiene branch September 27, 2026 20:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant