-
-
Notifications
You must be signed in to change notification settings - Fork 2.3k
feat: secure provider credential storage and legacy migration #1238
Copy link
Copy link
Open
Labels
autonomous: noNeeds your brain: a product/design decision is required before anyone acts.Needs your brain: a product/design decision is required before anyone acts.enhancementNew feature or requestNew feature or requesttriage: needs-decisionNeeds maintainer decision/design thoughtNeeds maintainer decision/design thought
Description
Activity
Metadata
Metadata
Assignees
Labels
autonomous: noNeeds your brain: a product/design decision is required before anyone acts.Needs your brain: a product/design decision is required before anyone acts.enhancementNew feature or requestNew feature or requesttriage: needs-decisionNeeds maintainer decision/design thoughtNeeds maintainer decision/design thought
Problem
Managed provider accounts and standalone Cursor/Antigravity credentials need a safer persistence boundary than plaintext JSON or environment files, while existing installations still need a compatibility migration path.
Proposed implementation
The reviewable fork branch below adds native OS secret-store persistence for managed credentials and standalone Cursor/Antigravity secrets. Account metadata remains in the provider pool JSON, legacy files remain readable for migration, new writes avoid plaintext credential backups, and no credentials are included in quota/health state.
Branch: https://github.com/yansigit/jcode/tree/feat/provider-pool-account-management-upstream
Compare: https://github.com/1jehuang/jcode/compare/master...yansigit:feat/provider-pool-account-management-upstream?expand=1
Verification
cargo check -p jcode-base -p jcode-storagepassed.Review notes
This is part of a broader account-pooling integration branch and can be submitted as a focused change or split further by maintainer preference. The branch also documents the native-keyring availability fallback and platform limitations.