Skip to content

fix(security): never persist the OAuth access token (v0.2.1) - #4

Merged
TheStreamCode merged 1 commit into
mainfrom
fix/credential-hygiene
Sep 27, 2026
Merged

TheStreamCode merged 1 commit into
mainfrom
fix/credential-hygiene

Conversation

@TheStreamCode

Copy link
Copy Markdown
Owner

write_cache sanitizes at the sink: only apiKey/accountId/email touch disk. Full-login test asserts oauthAccessToken absence from the raw file. README documents stored fields. Verified locally: 13 pytest green.

write_cache now persists only apiKey/accountId/email; the OAuth token stays in memory (nothing ever read it back). Full-login test asserts absence from the raw cache file. README documents the stored fields.
@TheStreamCode
TheStreamCode merged commit 6f53358 into main Sep 27, 2026
4 checks passed
@TheStreamCode
TheStreamCode deleted the fix/credential-hygiene branch September 27, 2026 20:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant