Skip to content

fix(ui): settings API Key title dedup + copy full key anytime (v1.22.1) - #95

Merged
argszero merged 1 commit into
mainfrom
feat/fix-apikey-copy
Aug 19, 2026
Merged

argszero merged 1 commit into
mainfrom
feat/fix-apikey-copy

Conversation

@argszero

Copy link
Copy Markdown
Owner

Summary

Fixes two settings-page issues reported by the host (rant 2026-08-19T18:06:25):

  1. Duplicate title — zh i18n value for the settings card title was API Key API keys; corrected to API Key.
  2. Copy full key anytime — the copy button showed a "full key shown only once at generation" toast because the full key was only kept in a session-only cache (Live.fullKeys) and the list API returned only masked keys. Now:
    • backend GET /api/api-keys returns an owner-visible full_key field (the masked key field stays the display value)
    • frontend copyKey() reads k.full_key from the list data, so copying works even after a page refresh; removed the Live.fullKeys session cache and the "shown once" logic; defensive fallback copies the masked key if full_key is missing
    • removed the now-unused settings.ak.copy.once i18n keys (zh/en)

Related Issue

Host rant 2026-08-19T18:06:25 (no issue number).

Changes

  • Backend: list_api_keys DAO adds full_key (owner-visible)
  • Frontend: copyKey() / renderSettings() / commitNewKey() use list full_key; Live.fullKeys removed
  • i18n: zh title dedup + remove settings.ak.copy.once (zh/en)
  • Docs: user-stories v1.22.1 entry

Tests

  • cargo test — 111/111 passed (extended api-keys list/delete tests: list contains full_key matching the generated key; masked key still contains ****; key absent from list after DELETE)
  • cargo fmt --check — clean
  • cargo clippy --all-targets -- -D warnings — clean
  • node --check app.js / i18n.js — clean
  • Live smoke (temp DB): register → verify → login → create key → list returns matching full_key → DELETE removes it

Checklist

  • Branch naming per convention (feat/fix-apikey-copy)
  • Conventional Commits message
  • Single-purpose, minimal diff (5 files)

Rant 2026-08-19T18:06:25 (host feedback):
1. zh i18n settings.apikey was 'API Key API keys' -> 'API Key'
2. copy button required the full key but list only returned a masked
   key and the frontend relied on a session-only cache (Live.fullKeys)
   that is lost after refresh -> 'full key shown once' toast.

Changes:
- backend: GET /api/api-keys now returns owner-visible full_key
  alongside the masked key (display stays masked, copy uses full)
- frontend: copyKey() reads k.full_key from the list data; removed
  the Live.fullKeys session cache and the 'shown once' logic;
  defensive fallback copies the masked key if full_key is missing
- i18n: removed settings.ak.copy.once (zh/en); fixed zh title
- tests: list contains full_key matching the generated key; key is
  gone from the list after DELETE (111/111 pass, clippy+fmt clean)
- docs: user-stories v1.22.1 entry
@argszero
argszero merged commit 799c18d into main Aug 19, 2026
1 check passed
argszero added a commit that referenced this pull request Sep 28, 2026
…toast (#320)

`settings.ak.gen.ok` (both packs) told the user the full API key is shown
"仅此一次" / "once". That sentence was true when it was written (#86, v1.21) and
stopped being true in v1.22.1 (#95): `GET /api/api-keys` now returns the
owner-visible `full_key` next to the masked `key` (`src/dao.rs`, pinned by
`routes::tests`), `copyKey()` copies it straight from the list data, and the
`Live.fullKeys` session cache is gone -- which is why #95's own message records
"removed ... the 'shown once' logic" and deletes the sibling string
`settings.ak.copy.once`.

#95 removed the logic and one carrier and left this one restating the retired
fact. The comment three lines below `copyKey()` still states the policy the
string violates: 「绝不提示「仅生成时展示一次」」.

Value-only fix; no key added or removed:

- zh: 已生成新 API Key「{name}」(完整 key 可在列表中随时复制)
- en: New API Key “{name}” generated (full key can be copied from the list anytime)

The sibling comment that repeated the same retired fact ("完整 key 仅生成时可得")
now names the mechanism, and `ui/index.html` bumps the two changed cache-bust
tokens.

No behaviour change: the list keeps showing the backend-masked value, the copy
button keeps handing out `full_key`, and the `{name}` slot is kept in both
packs. Key counts are untouched (688 keys before and after), so the i18n gates
still pass unchanged.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant