Repository navigation
Commit 809a864
committed
docs(drivers): say what the read path withholds from a plugin driver's config
The plugin-contributed-driver paragraph said `config` is "stored and served
to administrators as written". The write half holds: a driver with no
shipped contract gets no config verdict, so the row is stored as written.
The read half did not: `redactDatasourceConfig` hides the canonical
credential keys (`password`, `authToken`) and their former aliases at every
object depth, plus URL userinfo passwords and credential query parameters,
for every driver, contracted or not.
The paragraph now names that fixed, name-based set, says everything else is
served as written, and keeps the plugin author's responsibility and the
`external.credentialsRef` route. Docs only; no code change.
Claude-Session: https://claude.ai/code/session_01VF48aw8RPG6wzDnMgp6rtw
Co-authored-by: Claude <noreply@anthropic.com>1 parent 3c7785d commit 809a864
1 file changed
Lines changed: 12 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
154 | 154 | | |
155 | 155 | | |
156 | 156 | | |
157 | | - | |
158 | | - | |
159 | | - | |
160 | | - | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
161 | 169 | | |
162 | 170 | | |
163 | 171 | | |
| |||
0 commit comments