Skip to content

Latest commit

 

History

History
9 lines (7 loc) · 2.56 KB

File metadata and controls

9 lines (7 loc) · 2.56 KB

authentication — notes

Hand-written. ../harvested/authentication.md is what the documents say; this file is what the implementation found, and it wins. Each entry names the harvested entry it answers by that entry's stable key.

Superseded

  • Two renderings are one short: pp gives a Data its own #pretty_print, which walks the members and never calls an #inspect override, so a credential that redacts in #to_s and #inspect alone prints its secret under pp. Corrects authentication/f8a5bc6a ("Every credential type overrides both #inspect and #to_s to satisfy the redact-in-string-form requirement, since Ruby interpolation calls #to_s and a debugger calls #inspect"), whose two renderings are right and whose enumeration is incomplete for exactly the base type design §4 fixes for every value. Verified on 2026-09-18 against 3.2.11, 3.3.12, 3.4.10 and 4.0.6, identically: D = Data.define(:token) { def inspect = "#<redacted>" }, then PP.pp(D.new(token: "SECRET"), out), writes #<data D token="SECRET"> — pp.rb defines Data#pretty_print over members, and PP::ObjectMixin#pretty_print's "use #inspect when it is overridden" rule is what a plain class gets, not what a Data gets. A plain class with the same override pretty-prints through #inspect, so the two key-credential classes are safe by that route and the two Data credentials are not. AUTH-8 says "any string/diagnostic representation", and pp is the diagnostic representation a developer reaches for first. What the SDK does, per docs/work/mvp/phase6/phase6c/2026-09-09-phase6c-authentication-design.md's as-built row P6-72: Dexpace::Auth::BearerToken and Dexpace::Auth::PasswordCredential override #pretty_print(printer) as printer.text(inspect), the third rendering beside the two the rule names, and bearer_token_test.rb and password_credential_test.rb each assert the pp output; #to_h, #members and #deconstruct_keys still expose the real fields, which AUTH-8 permits (redaction "MUST NOT be achieved by mutating, nulling, or otherwise corrupting the real fields"). What it licenses for later phases: any Data that carries a secret — a phase-7 or downstream value type — needs all three overrides, and a test that pretty-prints it. What it does not license: treating Marshal, YAML or #to_h as renderings the object must redact; those are serialisations of the real fields and are the caller's. review · docs/work/mvp/phase6/phase6c/2026-09-09-phase6c-authentication-checklist.md · high · sha:manual-phase6c-data-pretty-print