Problem
When OS encryption is unavailable, replacing a saved GLM Coding Plan key publishes the new plaintext file before Orca knows whether that file could be restricted to the current user. If restoring the previous key then fails before the restore is published, the rejected new key remains on disk even though the save reports failure.
On Windows the requested file mode is ignored, so the leftover file can keep the parent directory's inherited permissions.
Proposed fix
After a failed restore, delete the credential file only when it still contains the rejected replacement. A restore that already published the previous key must not be deleted.
Problem
When OS encryption is unavailable, replacing a saved GLM Coding Plan key publishes the new plaintext file before Orca knows whether that file could be restricted to the current user. If restoring the previous key then fails before the restore is published, the rejected new key remains on disk even though the save reports failure.
On Windows the requested file mode is ignored, so the leftover file can keep the parent directory's inherited permissions.
Proposed fix
After a failed restore, delete the credential file only when it still contains the rejected replacement. A restore that already published the previous key must not be deleted.