Skip to content

fix(dashboard): show the API key fingerprint in the activation guide - #1166

Merged
jigjigjig merged 5 commits into
mainfrom
jigjigjig/fix-activation-key-mask
Sep 16, 2026
Merged

jigjigjig merged 5 commits into
mainfrom
jigjigjig/fix-activation-key-mask

Conversation

@jigjigjig

@jigjigjig jigjigjig commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

Description

The activation guide now shows the first eight and last four API-key characters, matching the key-creation dialog. The shared field provides the same inline reveal and copy controls. The key field and request examples share the same fingerprint until revealed. Short keys are fully concealed, and Copy still copies the complete key.

How to test it locally

  1. Build and start the dashboard with a provider configured.
  2. Create and select a fresh workspace, then open Overview.
  3. Confirm the activation sheet shows a partial key with inline eye and copy controls.
  4. Reveal and hide it; confirm the example follows. Copy while hidden and confirm it yields the full key.

Validated with make lint, dashboard lint/typecheck/build, all 23 activation component tests and 27 CopyField tests, and 12 onboarding browser tests. The full dashboard suite reported 6,409 passing tests and one unrelated Playground comparison failure; all 25 Playground tests passed on an isolated rerun. Browser tests used a temporary standalone-only server config because hybrid port 8010 is occupied locally. The live activation sheet was visually checked in the local demo.

PR Type

  • Bug Fix

Relevant issues

Follow-up to #1161 for the activation flow introduced in #1101.

Checklist

  • I understand the code I am submitting.
  • I have added or updated tests that cover my change.
  • I ran all backend Definition of Done checks locally (frontend-only change; validation above).
  • Documentation was updated where necessary (the existing API-key handoff guidance already describes this display).
  • If the API contract changed, I regenerated the OpenAPI spec (not applicable).

AI Usage

  • This is fully AI-generated.

AI Model/Tool used: GPT-6 / Codex

Any additional AI details you'd like to share: Implemented and self-reviewed against the repository frontend guidance.

  • I am an AI Agent filling out this form (check box if true)

Summary

  • The activation guide now shows the same API-key fingerprint as the key-creation dialog.
  • Users can reveal, hide, and copy the complete API key.
  • Short or invalid keys remain fully concealed.
  • Request examples use the same concealed or revealed key as the key field.

Technical notes

  • Added shared fingerprint handling in SetupSheet.
  • Added coverage for concealment, reveal and copy behavior.
  • Updated browser tests to verify the minted key across the field and request examples.

Validation

  • Linting, type checking, builds, activation tests, copy-field tests, onboarding browser tests, and dashboard tests passed.
  • One unrelated Playground comparison test failed in the full suite. All Playground tests passed when rerun separately.

Co-Authored-By: GPT-6 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

Warning

Review limit reached

Next included review available in 28 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used all 2 included reviews currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: ee62ba6a-1722-43d6-a199-af65a8b4f70d

📥 Commits

Reviewing files that changed from the base of the PR and between ad17d63 and f0c909d.

📒 Files selected for processing (4)
  • web/e2e/dashboard.spec.ts
  • web/e2e/helpers.ts
  • web/e2e/parity.management.spec.ts
  • web/src/features/onboarding/SetupGuide.test.tsx

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 9538863b-0039-491f-890a-9d0ce2a42be1

📥 Commits

Reviewing files that changed from the base of the PR and between c90f287 and ad17d63.

📒 Files selected for processing (3)
  • web/e2e/dashboard.spec.ts
  • web/src/features/onboarding/SetupGuide.test.tsx
  • web/src/features/onboarding/SetupSheet.tsx

Included review availability: Your plan provides up to 2 included reviews per hour; 1 remains after this review.


Walkthrough

Changes

API key concealment

Layer / File(s) Summary
Derived concealed API key display
web/src/features/onboarding/SetupSheet.tsx
SetupSheet derives a concealed value from apiKey. Available keys use a fingerprint, while unavailable keys use the default concealed value. Setup snippets and CopyField use this value.
Concealment and reveal validation
web/src/features/onboarding/SetupGuide.test.tsx, web/e2e/dashboard.spec.ts
Tests cover full concealment for short and malformed keys, fingerprint display, clipboard copying, and concealed, revealed, and re-hidden states in the dashboard flow.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to ad17d

No merge-blocking risk has been identified in the updated concealment flow.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 3 files.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title uses the Conventional Commit fix prefix with a scope, uses imperative mood, accurately describes the activation-guide change, and is 68 characters long.
Description check ✅ Passed The description includes all required sections, explains the user-facing change, provides local test steps and validation results, identifies the bug-fix type, links related issues, records checklist …
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch jigjigjig/fix-activation-key-mask
✨ Simplify code
  • Create PR with simplified code
  • Commit simplified code in branch jigjigjig/fix-activation-key-mask

Warning

Git: CodeRabbit could not clone the repository, so clone-backed analysis was skipped and this review may be incomplete. Verify repository clone access, such as SSH credentials, before requesting another full review. If clone access is intentionally unavailable, use path_filters to narrow the review scope.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@jigjigjig
jigjigjig requested review from a team, khaledosman and tbille and removed request for a team September 15, 2026 08:25

@khaledosman khaledosman left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The field half of this is right, but the snippet beside it was left on the old stand-in, so one credential now wears two of them on one screen. Two inline comments; the first is the blocking one.

Reviewed by Claude Opus 5 via Claude Code.

Comment thread web/src/features/onboarding/SetupSheet.tsx Outdated
Comment thread web/e2e/dashboard.spec.ts Outdated
@jigjigjig jigjigjig self-assigned this Sep 15, 2026
Co-Authored-By: GPT-6 <noreply@anthropic.com>
@jigjigjig
jigjigjig enabled auto-merge (squash) September 15, 2026 08:36

@jigjigjig jigjigjig left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Two test findings, neither blocking: one it.each case pins behavior SetupSheet.tsx:153 documents as wrong, and the browser test asserts the fingerprint's shape where it has the value to assert. The component change itself is clean and sweeps to the last call site (SettingsPage.tsx:341 keeps the plain stand-in correctly, per the settled spec: no stored prefix or suffix for the master key).

Title nit for the changelog line: the repo's settled word for this is fingerprint, and "show partial API keys" reads as a leak rather than a fix. fix(dashboard): show the API key fingerprint in the activation guide is the sentence I would release.

Reviewed by Claude Opus 5 via Claude Code.

Comment thread web/src/features/onboarding/SetupGuide.test.tsx Outdated
Comment thread web/e2e/dashboard.spec.ts Outdated
The activation and key-creation browser tests matched the stand-in by
shape, which any key of the right length satisfies. Both derive it from
the minted secret instead. Drops the empty-key case from the activation
unit test: the sheet's own guard rules that state out, and the mint
cannot produce it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@jigjigjig jigjigjig changed the title fix(dashboard): show partial API keys in the activation guide fix(dashboard): show the API key fingerprint in the activation guide Sep 16, 2026

@khaledosman khaledosman left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The earlier findings are addressed: SetupSheet routes through concealedFingerprint rather than reimplementing it, and both specs now pin the stand-in to the key that was actually minted instead of to a shape any key would match. Three small test-hygiene points inline; none blocking.

🤖 Review generated with Claude Code (Opus 5)

Comment thread web/src/features/onboarding/SetupGuide.test.tsx Outdated
Comment thread web/src/features/onboarding/SetupGuide.test.tsx Outdated
Comment thread web/e2e/parity.management.spec.ts Outdated
Co-Authored-By: GPT-6 <noreply@anthropic.com>
@jigjigjig
jigjigjig merged commit c2d7e2e into main Sep 16, 2026
9 checks passed
@jigjigjig
jigjigjig deleted the jigjigjig/fix-activation-key-mask branch September 16, 2026 11:15
@njbrake njbrake mentioned this pull request Sep 16, 2026
4 tasks done
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants