Skip to content

Commit 6a4fb54

Browse files
committed
docs(changeset): state the remedy as prose; no key is retired
Claude-Session: https://claude.ai/code/session_018zT8d8NpiQ1ExhuNd5TxY6 Co-Authored-By: Claude <noreply@anthropic.com>
1 parent f19ea59 commit 6a4fb54

1 file changed

Lines changed: 7 additions & 9 deletions

File tree

‎.changeset/21840-contractless-datasource-credentials.md‎

Lines changed: 7 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -48,15 +48,13 @@ own `config.<path>`:
4848
stored), a non-string value under a credential-shaped name, array data, and every
4949
other key — the config shape itself stays unjudged.
5050

51-
### FROM → TO
52-
53-
| before | what to write instead |
54-
| --- | --- |
55-
| `config.apiKey: 'sk-…'` (or any credential-shaped key) on a contractless driver | remove it and bind the secret: the connection form's secret field, or `external.credentialsRef`. The connect path hands the decrypted value to the driver factory as the connection secret, so the plugin driver's factory must read that injected secret. |
56-
| `config.connectionString: 'Server=h;Password=p'` | `config.connectionString: 'Server=h'`, and bind the password the same way. |
57-
58-
**The one-line fix: delete the inline credential from `config` and bind it as the
59-
datasource's secret.**
51+
**What an author sees now, and the remedy it names.** Each refusal is a `custom` issue
52+
at the value's own `config.<path>`, naming the position and the remedy: remove the
53+
inline credential from `config` and bind it as the datasource's secret — the
54+
connection form's secret field, or `external.credentialsRef`. The connect path hands
55+
the decrypted value to the driver factory as the connection secret, so a plugin
56+
driver receives it only if its factory reads that injected secret. No key is retired
57+
or renamed; nothing an author wrote is rewritten.
6058

6159
**Every read door withholds it, rows stored before this release included.** The one
6260
read-path redactor (`redactDatasourceConfig`) now also drops, for a contractless

0 commit comments

Comments
 (0)