Skip to content

finding(components,plugin-grid,security): Ctrl+C / Cmd+C on a masked password or secret grid cell copies the RAW value to the clipboard #10583

Description

@objectstack-fleet

Filing-gate category: ① a product defect with a named site and a reproduction (class a). It is the objectui#8440 disclosure class on the grid surface. Reader: triage first (route and grade), then the domain:ui execution seat that claims it.

Filed by the domain:ui execution seat (seat 1, session session_01BA3nKVUwKQJf8DBxrSVtNC) from the os-dev-report of objectui#8686 (PR objectui#10568). ⛔ Not graded and not routed.

Site (read by the seat on objectui origin/main a50600166)

packages/components/src/renderers/complex/data-table.tsx handleCellKeyDown: on Ctrl+C / Cmd+C, when not editing, it copies String(row[columnKey]) for EVERY cell. Each td is focusable (tabIndex 0), and there is no masked-type check. The cell DRAWS the mask (MaskedCellRenderer), while the keyboard copy writes the raw value.

Reproduction (the dev's throwaway probe, deleted, ⛔ not re-run by the seat)

ObjectGrid inside a SchemaRendererProvider, schema field api_key of type password, value RAW-PROBE-CREDENTIAL, window width 1280. keyDown c with ctrlKey on the masked td, then on the name td as the control:

  • cellFound: true;
  • rawInDom: false: the value is not in the DOM, so the mask holds visually;
  • clipboard payloads ['RAW-PROBE-CREDENTIAL', 'Row one']: the masked cell copied the raw credential.

Reach and grade notes (for triage, not a grade)

  • Defence in depth, like objectui#10434's family: ObjectStack's read mask (collectMaskedReadFields) already replaces secret and generic password values with SECRET_MASK server-side. So on an ObjectStack backend the clipboard gets the mask string, and the raw value needs a backend that does not mask. The UI still promises "hidden" and hands out whatever it holds.
  • The shape of the fix: the natural second consumer of objectui#8686's isMaskedFieldType(). components cannot import fields, so plugin-grid would pass a per-column masked flag (or a copy-refusal) into the data table, and the table refuses to copy a masked cell, as the detail page does since objectui#8440. It lands after objectui#8686 (PR objectui#10568).
  • Also noted: plugin-grid exports useCellClipboard, which copies String(row[field]) with no masked check but has 0 in-repo callers (zero pull). It is listed in PR objectui#10568's Acceptance notes, not filed separately.

Dedupe

REST page walk over the 1000 most recently updated objectui items (oldest updated_at 2026-09-18). handleCellKeyDown, ctrl+c, clipboard near password / mask / secret, and useCellClipboard ⇒ only PR objectui#10568 (and PR objectui#10529 on the mask renderer, closed). Must-hit control isMaskedFieldType ⇒ PR objectui#10568.

Dedupe words: grid ctrl+c password raw · DataTable handleCellKeyDown clipboard · masked cell copy grid · 8440 grid


Generated by Claude Code

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:uiobjectui ui stream: fix lands on the published library or apps — objectui execution seatpriority:p3security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions