fix(dashboard): show the API key fingerprint in the activation guide - #1166
Conversation
Co-Authored-By: GPT-6 <noreply@anthropic.com>
|
Warning Review limit reachedNext included review available in 28 minutes. View limit detailsLimit details: You’ve used all 2 included reviews currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (4)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (3)
Included review availability: Your plan provides up to 2 included reviews per hour; 1 remains after this review. WalkthroughChangesAPI key concealment
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to No merge-blocking risk has been identified in the updated concealment flow. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
✨ Simplify code
Warning Git: CodeRabbit could not clone the repository, so clone-backed analysis was skipped and this review may be incomplete. Verify repository clone access, such as SSH credentials, before requesting another full review. If clone access is intentionally unavailable, use Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
khaledosman
left a comment
There was a problem hiding this comment.
The field half of this is right, but the snippet beside it was left on the old stand-in, so one credential now wears two of them on one screen. Two inline comments; the first is the blocking one.
Reviewed by Claude Opus 5 via Claude Code.
Co-Authored-By: GPT-6 <noreply@anthropic.com>
jigjigjig
left a comment
There was a problem hiding this comment.
Two test findings, neither blocking: one it.each case pins behavior SetupSheet.tsx:153 documents as wrong, and the browser test asserts the fingerprint's shape where it has the value to assert. The component change itself is clean and sweeps to the last call site (SettingsPage.tsx:341 keeps the plain stand-in correctly, per the settled spec: no stored prefix or suffix for the master key).
Title nit for the changelog line: the repo's settled word for this is fingerprint, and "show partial API keys" reads as a leak rather than a fix. fix(dashboard): show the API key fingerprint in the activation guide is the sentence I would release.
Reviewed by Claude Opus 5 via Claude Code.
The activation and key-creation browser tests matched the stand-in by shape, which any key of the right length satisfies. Both derive it from the minted secret instead. Drops the empty-key case from the activation unit test: the sheet's own guard rules that state out, and the mint cannot produce it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
khaledosman
left a comment
There was a problem hiding this comment.
The earlier findings are addressed: SetupSheet routes through concealedFingerprint rather than reimplementing it, and both specs now pin the stand-in to the key that was actually minted instead of to a shape any key would match. Three small test-hygiene points inline; none blocking.
🤖 Review generated with Claude Code (Opus 5)
Co-Authored-By: GPT-6 <noreply@anthropic.com>
Description
The activation guide now shows the first eight and last four API-key characters, matching the key-creation dialog. The shared field provides the same inline reveal and copy controls. The key field and request examples share the same fingerprint until revealed. Short keys are fully concealed, and Copy still copies the complete key.
How to test it locally
Validated with
make lint, dashboard lint/typecheck/build, all 23 activation component tests and 27 CopyField tests, and 12 onboarding browser tests. The full dashboard suite reported 6,409 passing tests and one unrelated Playground comparison failure; all 25 Playground tests passed on an isolated rerun. Browser tests used a temporary standalone-only server config because hybrid port 8010 is occupied locally. The live activation sheet was visually checked in the local demo.PR Type
Relevant issues
Follow-up to #1161 for the activation flow introduced in #1101.
Checklist
AI Usage
AI Model/Tool used: GPT-6 / Codex
Any additional AI details you'd like to share: Implemented and self-reviewed against the repository frontend guidance.
Summary
Technical notes
SetupSheet.Validation