Skip to content

feat: secure provider credential storage and legacy migration #1238

Description

@yansigit

Problem

Managed provider accounts and standalone Cursor/Antigravity credentials need a safer persistence boundary than plaintext JSON or environment files, while existing installations still need a compatibility migration path.

Proposed implementation

The reviewable fork branch below adds native OS secret-store persistence for managed credentials and standalone Cursor/Antigravity secrets. Account metadata remains in the provider pool JSON, legacy files remain readable for migration, new writes avoid plaintext credential backups, and no credentials are included in quota/health state.

Branch: https://github.com/yansigit/jcode/tree/feat/provider-pool-account-management-upstream
Compare: https://github.com/1jehuang/jcode/compare/master...yansigit:feat/provider-pool-account-management-upstream?expand=1

Verification

  • Focused managed and standalone credential persistence tests passed.
  • cargo check -p jcode-base -p jcode-storage passed.
  • Public account/usage JSON checks passed without exposing secrets.
  • Legacy compatibility behavior remains covered; native writes remove plaintext copies only after a successful native save.

Review notes

This is part of a broader account-pooling integration branch and can be submitted as a focused change or split further by maintainer preference. The branch also documents the native-keyring availability fallback and platform limitations.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    autonomous: noNeeds your brain: a product/design decision is required before anyone acts.enhancementNew feature or requesttriage: needs-decisionNeeds maintainer decision/design thought

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions