Skip to content

Commit 809a864

Browse files
committed
docs(drivers): say what the read path withholds from a plugin driver's config
The plugin-contributed-driver paragraph said `config` is "stored and served to administrators as written". The write half holds: a driver with no shipped contract gets no config verdict, so the row is stored as written. The read half did not: `redactDatasourceConfig` hides the canonical credential keys (`password`, `authToken`) and their former aliases at every object depth, plus URL userinfo passwords and credential query parameters, for every driver, contracted or not. The paragraph now names that fixed, name-based set, says everything else is served as written, and keeps the plugin author's responsibility and the `external.credentialsRef` route. Docs only; no code change. Claude-Session: https://claude.ai/code/session_01VF48aw8RPG6wzDnMgp6rtw Co-authored-by: Claude <noreply@anthropic.com>
1 parent 3c7785d commit 809a864

1 file changed

Lines changed: 12 additions & 4 deletions

File tree

‎content/docs/data-modeling/drivers.mdx‎

Lines changed: 12 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -154,10 +154,18 @@ Two things live **outside** `config`, because they are not driver-specific:
154154

155155
A plugin-contributed driver (`com.vendor.snowflake`) has no contract in this
156156
repo, so its `config` is left unvalidated rather than judged against a shape the
157-
platform does not have. The platform also does not guess which of its keys hold
158-
credentials: `config` is stored and served to administrators as written. Keeping
159-
secrets out of it is the plugin author's responsibility; put the credential in
160-
the bound secret (`external.credentialsRef`) instead.
157+
platform does not have, and is stored as written. The platform also does not
158+
guess which of its keys hold credentials. On read it withholds only what it
159+
withholds for every driver: a key named exactly `password` or `authToken`, or
160+
one of their former aliases (`FORMER_CREDENTIAL_ALIASES`), and, in a URL-shaped
161+
string value, the password in its userinfo and its credential query parameters
162+
(`CREDENTIAL_URL_QUERY_PARAM_NAMES`, such as `?password=`). Both apply at every
163+
depth of nested objects, but not inside arrays. Everything else in `config` is
164+
served to administrators as written (`redactDatasourceConfig` in
165+
`datasource-credential-redaction.ts`), and a withheld value still sits in the
166+
stored row. Keeping secrets out of `config` is the plugin author's
167+
responsibility; put the credential in the bound secret
168+
(`external.credentialsRef`) instead.
161169

162170
<Callout type="info">
163171
The same schemas are projected to JSON Schema for

0 commit comments

Comments
 (0)