fix(ui): settings API Key title dedup + copy full key anytime (v1.22.1) - #95
Merged
Merged
Conversation
Rant 2026-08-19T18:06:25 (host feedback): 1. zh i18n settings.apikey was 'API Key API keys' -> 'API Key' 2. copy button required the full key but list only returned a masked key and the frontend relied on a session-only cache (Live.fullKeys) that is lost after refresh -> 'full key shown once' toast. Changes: - backend: GET /api/api-keys now returns owner-visible full_key alongside the masked key (display stays masked, copy uses full) - frontend: copyKey() reads k.full_key from the list data; removed the Live.fullKeys session cache and the 'shown once' logic; defensive fallback copies the masked key if full_key is missing - i18n: removed settings.ak.copy.once (zh/en); fixed zh title - tests: list contains full_key matching the generated key; key is gone from the list after DELETE (111/111 pass, clippy+fmt clean) - docs: user-stories v1.22.1 entry
7 tasks done
argszero
added a commit
that referenced
this pull request
Sep 28, 2026
…toast (#320) `settings.ak.gen.ok` (both packs) told the user the full API key is shown "仅此一次" / "once". That sentence was true when it was written (#86, v1.21) and stopped being true in v1.22.1 (#95): `GET /api/api-keys` now returns the owner-visible `full_key` next to the masked `key` (`src/dao.rs`, pinned by `routes::tests`), `copyKey()` copies it straight from the list data, and the `Live.fullKeys` session cache is gone -- which is why #95's own message records "removed ... the 'shown once' logic" and deletes the sibling string `settings.ak.copy.once`. #95 removed the logic and one carrier and left this one restating the retired fact. The comment three lines below `copyKey()` still states the policy the string violates: 「绝不提示「仅生成时展示一次」」. Value-only fix; no key added or removed: - zh: 已生成新 API Key「{name}」(完整 key 可在列表中随时复制) - en: New API Key “{name}” generated (full key can be copied from the list anytime) The sibling comment that repeated the same retired fact ("完整 key 仅生成时可得") now names the mechanism, and `ui/index.html` bumps the two changed cache-bust tokens. No behaviour change: the list keeps showing the backend-masked value, the copy button keeps handing out `full_key`, and the `{name}` slot is kept in both packs. Key counts are untouched (688 keys before and after), so the i18n gates still pass unchanged.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes two settings-page issues reported by the host (rant
2026-08-19T18:06:25):API Key API keys; corrected toAPI Key.Live.fullKeys) and the list API returned only masked keys. Now:GET /api/api-keysreturns an owner-visiblefull_keyfield (the maskedkeyfield stays the display value)copyKey()readsk.full_keyfrom the list data, so copying works even after a page refresh; removed theLive.fullKeyssession cache and the "shown once" logic; defensive fallback copies the masked key iffull_keyis missingsettings.ak.copy.oncei18n keys (zh/en)Related Issue
Host rant
2026-08-19T18:06:25(no issue number).Changes
list_api_keysDAO addsfull_key(owner-visible)copyKey()/renderSettings()/commitNewKey()use listfull_key;Live.fullKeysremovedsettings.ak.copy.once(zh/en)Tests
cargo test— 111/111 passed (extended api-keys list/delete tests: list containsfull_keymatching the generated key; masked key still contains****; key absent from list after DELETE)cargo fmt --check— cleancargo clippy --all-targets -- -D warnings— cleannode --checkapp.js / i18n.js — cleanfull_key→ DELETE removes itChecklist
feat/fix-apikey-copy)