Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
carriesCredentialsflag the Apply path reads to keep those statements out of history, so nothing kept the password out of the editor.Tests
PrincipalOpenInEditorTests(new): a staged create foralicewiths3cretand a staged password change forbobgive editor scripts with<password>in place of the password; Apply still carries the real password and thecarriesCredentialsflag; a create without a password is unchanged; statements keep their execution order. Four view-model cases stage changes throughUsersRolesViewModelon an injected MySQL principal driver and check the script Review hands Open in Query Editor, the review sheet's notice that the script holds<password>, no notice without a password, and that Discard clears both. The password and view-model cases fail without the fix: built from the unmasked statements, the scripts contains3cretandn3w-s3cretand no notice appears.PrincipalStatementGeneratorTests: a driver that never writes the password (as Typesense does) reports nothing hidden, so the sheet does not announce a placeholder that is not in the script.PrincipalChangeManagerTestscovers the staged-create fold, which now shares the password-replacing initializer.No UI test: the review sheet needs a live MySQL or PostgreSQL server with Users & Roles, which the UI test runner does not have. The editor text and the notice are decided in the view model, which the unit tests cover.
Docs
The docs rewrite branch covers the user-facing text for Users & Roles.
CI fixes
The failed Package Tests job was
SyncRecordMapperTests.unknownWireValueFailsClosed. Its duplicate decoder treated an unknown Safe Mode value as Off. Sync decoding now usesSafeModeLevel(wireValue:isReadOnly:), requiring confirmation and preserving legacy read-only restrictions. Added regressions for unknown read-only values and renames that preserve an unknown wire value.Integrated main at
3cf419ce1, keeping both Security changelog entries. Also corrected the confirmed SurrealDB compile defect from main: its callers still passed text length after the JSON helper became a property. The helper once again accepts text length, keeping valid display truncation and full export text.Validation for these fixes:
TableProApp/rust-dameng,Contents/MacOS,Contents/Helpers,/Applications/Xcode-beta.app).Pushing this commit triggers fresh GitHub Actions runs.
Unit-test compile correction
The unit-test build exposed three fixtures still calling the old one-argument cell API: two in Typesense and one in Elasticsearch. They now explicitly pass
length: .display, retaining their expected display truncation and write-refusal behavior.Both fixture files are identical on all four updated branches. The complete test target built on #3183, with all 87 selected storage and write-refusal tests passing. Separately, an isolated SwiftPM build of all Elasticsearch and Typesense driver sources and the actual driver test files passed 175 tests in 14 suites on this branch. SwiftLint found no violations in the two fixture files.