') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); chore(status): bt status prints which secret storage is used by viadezo1er · Pull Request #341 · braintrustdata/bt · GitHub
Skip to content

chore(status): bt status prints which secret storage is used - #341

Open
Cedric / ViaDézo1er (viadezo1er) wants to merge 1 commit into
mainfrom
cedric/clarify-credential-metadata-vs-secret-storage
Open

chore(status): bt status prints which secret storage is used#341
Cedric / ViaDézo1er (viadezo1er) wants to merge 1 commit into
mainfrom
cedric/clarify-credential-metadata-vs-secret-storage

Conversation

@viadezo1er

@viadezo1erCedric / ViaDézo1er (viadezo1er) commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

clarifies that config.json is metadata and not secrets

Read the description of #344, this PR might need tweaking to better support Windows.

Before:

✓ cedric — https://www.braintrust.dev — oauth — api: https://api.braintrust.dev — Cedric Halber (cedric@braintrustdata.com)
✓ cedric-2 — http://localhost:3000 — oauth — api: http://localhost:8000 — Cédric Halber (cedric@braintrustdata.com)
✓ profile — https://www.braintrust.dev — api_key — bt-****vVjh3
Credentials: /Users/cedric@braintrustdata.com/.config/bt/auth.json
org: ced
project: My Project
project_id: 8bd69204-1f16-4eef-b8ce-74f20bede6f7
profile: cedric-2
app_url: http://localhost:3000
api_url: http://localhost:8000
auth: oauth — Cédric Halber (cedric@braintrustdata.com)
source: /Users/cedric@braintrustdata.com/.bt/config.json

After:

✓ cedric — https://www.braintrust.dev — oauth — api: https://api.braintrust.dev — Cedric Halber (cedric@braintrustdata.com)
✓ cedric-2 — http://localhost:3000 — oauth — api: http://localhost:8000 — Cédric Halber (cedric@braintrustdata.com)
✓ profile — https://www.braintrust.dev — api_key — bt-****vVjh3
Secret storage: macOS Keychain
Profile metadata: /Users/cedric@braintrustdata.com/.config/bt/auth.json
org: ced
project: My Project
project_id: e52400bc-f0f5-4d60-81ce-c1dd7aa933d1
profile: cedric-2
app_url: http://localhost:3000
api_url: http://localhost:8000
auth: oauth — Cédric Halber (cedric@braintrustdata.com)
source: /Users/cedric@braintrustdata.com/.config/bt/config.json

clarifies that config.json is metadata and not secrets
@github-actions

Copy link
Copy Markdown
Contributor

Latest downloadable build artifacts for this PR commit ef6de491efd7:

Available artifact names
  • artifacts-build-global
  • artifacts-build-local-x86_64-apple-darwin
  • artifacts-build-local-x86_64-pc-windows-msvc
  • artifacts-build-local-aarch64-pc-windows-msvc
  • artifacts-build-local-aarch64-apple-darwin
  • artifacts-build-local-x86_64-unknown-linux-musl
  • artifacts-build-local-x86_64-unknown-linux-gnu
  • artifacts-build-local-aarch64-unknown-linux-gnu
  • artifacts-plan-dist-manifest
  • cargo-dist-cache

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:ef6de491ef

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "Codex (@codex) review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "Codex (@codex) address that feedback".

Comment threadsrc/auth.rs
Comment on lines +2185 to +2187
SecretStorageInfo {
backend: SECURE_STORAGE_BACKEND.expect("secure storage backend checked above"),
path: None,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Verify the secure backend before reporting it

On Linux or macOS, when the secure-store utility or service is unavailable and secrets.json is absent or empty, this branch reports the platform secure backend solely from the compile target. For example, a Linux installation without secret-tool can show Linux Secret Service (via secret-tool) even while profile verification reports a missing credential and any subsequent save would fall back to plaintext. Probe backend availability or report that no active backend was detected instead of claiming the secure backend is in use.

Useful? React with 👍 / 👎.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@viadezo1er