AIT-66: correct stale ac_-Bearer-token docstrings - #26

Merged
ord669 merged 1 commit into
mainfrom
ait-66-api-key-audit-nits
Jul 18, 2026
Merged

AIT-66: correct stale ac_-Bearer-token docstrings#26
ord669 merged 1 commit into
mainfrom
ait-66-api-key-audit-nits

Conversation

@ord669

@ord669ord669 commented Jul 18, 2026

Copy link
Copy Markdown
Contributor

Refs AIT-66 (item 6 of the audit-nit batch; main fixes in hookmyapp/hookmyapp#108)

Docstring/fixture sweep only — no runtime changes:

  • Comments claiming keys are "ac_ Bearer tokens" corrected: the Bearer secret is an opaque hmok_ token; ac_ is the credential's public row id (see backend agent-token-prefix.ts).
  • Test fixtures renamed ac_live_*hmok_live_* so they model the real token shape.

19 affected tests green, tsc clean. (3 pre-existing cli-error-integration.test.ts failures reproduce on clean main — unrelated, tracked under AIT-171.)

Summary by CodeRabbit

  • Documentation

    • Clarified that agent access tokens are opaque hmok_… Bearer tokens.
    • Distinguished secret access tokens from their associated ac_ public credential IDs.
    • Updated authentication, credential management, logout, and credential storage guidance to reflect the current terminology.
  • Tests

    • Updated authentication and refresh scenarios to use the current access-token format.

…mok_, ac_ is the credential public id (AIT-66)
@coderabbitai

coderabbitaiBot commented Jul 18, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 8d00011f-3bdc-4a8d-b32f-1be5684f7033

📥 Commits

Reviewing files that changed from the base of the PR and between 60caee9 and a8ff399.

📒 Files selected for processing (8)
  • src/api/__tests__/agent-auth.test.ts
  • src/api/__tests__/agent-refresh.test.ts
  • src/api/agent-auth.ts
  • src/auth/__tests__/agentmd-login.test.ts
  • src/auth/login.ts
  • src/auth/logout.ts
  • src/commands/credentials.ts
  • src/storage/secrets.ts

📝 Walkthrough

Walkthrough

Agent credential fixtures, assertions, and documentation now use opaque hmok_ access tokens while identifying credentials by their ac_ public ids. No runtime logic or public API declarations changed.

Changes

Agent credential token alignment

Layer / File(s)Summary
Token fixtures, assertions, and documentation
src/api/..., src/auth/..., src/commands/credentials.ts, src/storage/secrets.ts
Updated agent-auth and login test values to hmok_live_*, and clarified that persisted tokens are opaque hmok_ Bearer tokens distinct from ac_ public ids.

Estimated code review effort: 1 (Trivial) | ~3 minutes

Possibly related PRs

  • hookmyapp/cli#9: Related agent/auth.md login flow and agent-credential token handling updates.
  • hookmyapp/cli#14: Related OTP login tests and claim-completion token expectations.
  • hookmyapp/cli#21: Related agent-credential token and refresh-flow changes.

Suggested reviewers:ordvir

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 66.67% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title is specific, concise, and accurately reflects the main docstring terminology update in the PR.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ait-66-api-key-audit-nits

Comment @coderabbitai help to get the list of available commands.

@ord669
ord669 merged commit bc116be into mainJul 18, 2026
3 checks passed
@ord669
ord669 deleted the ait-66-api-key-audit-nits branch July 18, 2026 13:32
ord669 added a commit that referenced this pull request Aug 12, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ord669
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

AIT-66: correct stale ac_-Bearer-token docstrings - #26

Merged
ord669 merged 1 commit into
mainfrom
ait-66-api-key-audit-nits
Jul 18, 2026
Merged

AIT-66: correct stale ac_-Bearer-token docstrings#26
ord669 merged 1 commit into
mainfrom
ait-66-api-key-audit-nits

Conversation

@ord669

@ord669ord669 commented Jul 18, 2026

Copy link
Copy Markdown
Contributor

Refs AIT-66 (item 6 of the audit-nit batch; main fixes in hookmyapp/hookmyapp#108)

Docstring/fixture sweep only — no runtime changes:

  • Comments claiming keys are "ac_ Bearer tokens" corrected: the Bearer secret is an opaque hmok_ token; ac_ is the credential's public row id (see backend agent-token-prefix.ts).
  • Test fixtures renamed ac_live_*hmok_live_* so they model the real token shape.

19 affected tests green, tsc clean. (3 pre-existing cli-error-integration.test.ts failures reproduce on clean main — unrelated, tracked under AIT-171.)

Summary by CodeRabbit

  • Documentation

    • Clarified that agent access tokens are opaque hmok_… Bearer tokens.
    • Distinguished secret access tokens from their associated ac_ public credential IDs.
    • Updated authentication, credential management, logout, and credential storage guidance to reflect the current terminology.
  • Tests

    • Updated authentication and refresh scenarios to use the current access-token format.

…mok_, ac_ is the credential public id (AIT-66)
@coderabbitai

coderabbitaiBot commented Jul 18, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 8d00011f-3bdc-4a8d-b32f-1be5684f7033

📥 Commits

Reviewing files that changed from the base of the PR and between 60caee9 and a8ff399.

📒 Files selected for processing (8)
  • src/api/__tests__/agent-auth.test.ts
  • src/api/__tests__/agent-refresh.test.ts
  • src/api/agent-auth.ts
  • src/auth/__tests__/agentmd-login.test.ts
  • src/auth/login.ts
  • src/auth/logout.ts
  • src/commands/credentials.ts
  • src/storage/secrets.ts

📝 Walkthrough

Walkthrough

Agent credential fixtures, assertions, and documentation now use opaque hmok_ access tokens while identifying credentials by their ac_ public ids. No runtime logic or public API declarations changed.

Changes

Agent credential token alignment

Layer / File(s)Summary
Token fixtures, assertions, and documentation
src/api/..., src/auth/..., src/commands/credentials.ts, src/storage/secrets.ts
Updated agent-auth and login test values to hmok_live_*, and clarified that persisted tokens are opaque hmok_ Bearer tokens distinct from ac_ public ids.

Estimated code review effort: 1 (Trivial) | ~3 minutes

Possibly related PRs

  • hookmyapp/cli#9: Related agent/auth.md login flow and agent-credential token handling updates.
  • hookmyapp/cli#14: Related OTP login tests and claim-completion token expectations.
  • hookmyapp/cli#21: Related agent-credential token and refresh-flow changes.

Suggested reviewers:ordvir

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 66.67% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title is specific, concise, and accurately reflects the main docstring terminology update in the PR.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ait-66-api-key-audit-nits

Comment @coderabbitai help to get the list of available commands.

@ord669
ord669 merged commit bc116be into mainJul 18, 2026
3 checks passed
@ord669
ord669 deleted the ait-66-api-key-audit-nits branch July 18, 2026 13:32
ord669 added a commit that referenced this pull request Aug 12, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ord669
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

AIT-66: correct stale ac_-Bearer-token docstrings - #26

Merged
ord669 merged 1 commit into
mainfrom
ait-66-api-key-audit-nits
Jul 18, 2026
Merged

AIT-66: correct stale ac_-Bearer-token docstrings#26
ord669 merged 1 commit into
mainfrom
ait-66-api-key-audit-nits

Conversation

@ord669

@ord669ord669 commented Jul 18, 2026

Copy link
Copy Markdown
Contributor

Refs AIT-66 (item 6 of the audit-nit batch; main fixes in hookmyapp/hookmyapp#108)

Docstring/fixture sweep only — no runtime changes:

  • Comments claiming keys are "ac_ Bearer tokens" corrected: the Bearer secret is an opaque hmok_ token; ac_ is the credential's public row id (see backend agent-token-prefix.ts).
  • Test fixtures renamed ac_live_*hmok_live_* so they model the real token shape.

19 affected tests green, tsc clean. (3 pre-existing cli-error-integration.test.ts failures reproduce on clean main — unrelated, tracked under AIT-171.)

Summary by CodeRabbit

  • Documentation

    • Clarified that agent access tokens are opaque hmok_… Bearer tokens.
    • Distinguished secret access tokens from their associated ac_ public credential IDs.
    • Updated authentication, credential management, logout, and credential storage guidance to reflect the current terminology.
  • Tests

    • Updated authentication and refresh scenarios to use the current access-token format.

…mok_, ac_ is the credential public id (AIT-66)
@coderabbitai

coderabbitaiBot commented Jul 18, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 8d00011f-3bdc-4a8d-b32f-1be5684f7033

📥 Commits

Reviewing files that changed from the base of the PR and between 60caee9 and a8ff399.

📒 Files selected for processing (8)
  • src/api/__tests__/agent-auth.test.ts
  • src/api/__tests__/agent-refresh.test.ts
  • src/api/agent-auth.ts
  • src/auth/__tests__/agentmd-login.test.ts
  • src/auth/login.ts
  • src/auth/logout.ts
  • src/commands/credentials.ts
  • src/storage/secrets.ts

📝 Walkthrough

Walkthrough

Agent credential fixtures, assertions, and documentation now use opaque hmok_ access tokens while identifying credentials by their ac_ public ids. No runtime logic or public API declarations changed.

Changes

Agent credential token alignment

Layer / File(s)Summary
Token fixtures, assertions, and documentation
src/api/..., src/auth/..., src/commands/credentials.ts, src/storage/secrets.ts
Updated agent-auth and login test values to hmok_live_*, and clarified that persisted tokens are opaque hmok_ Bearer tokens distinct from ac_ public ids.

Estimated code review effort: 1 (Trivial) | ~3 minutes

Possibly related PRs

  • hookmyapp/cli#9: Related agent/auth.md login flow and agent-credential token handling updates.
  • hookmyapp/cli#14: Related OTP login tests and claim-completion token expectations.
  • hookmyapp/cli#21: Related agent-credential token and refresh-flow changes.

Suggested reviewers:ordvir

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 66.67% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title is specific, concise, and accurately reflects the main docstring terminology update in the PR.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ait-66-api-key-audit-nits

Comment @coderabbitai help to get the list of available commands.

@ord669
ord669 merged commit bc116be into mainJul 18, 2026
3 checks passed
@ord669
ord669 deleted the ait-66-api-key-audit-nits branch July 18, 2026 13:32
ord669 added a commit that referenced this pull request Aug 12, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ord669
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

AIT-66: correct stale ac_-Bearer-token docstrings - #26

Merged
ord669 merged 1 commit into
mainfrom
ait-66-api-key-audit-nits
Jul 18, 2026
Merged

AIT-66: correct stale ac_-Bearer-token docstrings#26
ord669 merged 1 commit into
mainfrom
ait-66-api-key-audit-nits

Conversation

@ord669

@ord669ord669 commented Jul 18, 2026

Copy link
Copy Markdown
Contributor

Refs AIT-66 (item 6 of the audit-nit batch; main fixes in hookmyapp/hookmyapp#108)

Docstring/fixture sweep only — no runtime changes:

  • Comments claiming keys are "ac_ Bearer tokens" corrected: the Bearer secret is an opaque hmok_ token; ac_ is the credential's public row id (see backend agent-token-prefix.ts).
  • Test fixtures renamed ac_live_*hmok_live_* so they model the real token shape.

19 affected tests green, tsc clean. (3 pre-existing cli-error-integration.test.ts failures reproduce on clean main — unrelated, tracked under AIT-171.)

Summary by CodeRabbit

  • Documentation

    • Clarified that agent access tokens are opaque hmok_… Bearer tokens.
    • Distinguished secret access tokens from their associated ac_ public credential IDs.
    • Updated authentication, credential management, logout, and credential storage guidance to reflect the current terminology.
  • Tests

    • Updated authentication and refresh scenarios to use the current access-token format.

…mok_, ac_ is the credential public id (AIT-66)
@coderabbitai

coderabbitaiBot commented Jul 18, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 8d00011f-3bdc-4a8d-b32f-1be5684f7033

📥 Commits

Reviewing files that changed from the base of the PR and between 60caee9 and a8ff399.

📒 Files selected for processing (8)
  • src/api/__tests__/agent-auth.test.ts
  • src/api/__tests__/agent-refresh.test.ts
  • src/api/agent-auth.ts
  • src/auth/__tests__/agentmd-login.test.ts
  • src/auth/login.ts
  • src/auth/logout.ts
  • src/commands/credentials.ts
  • src/storage/secrets.ts

📝 Walkthrough

Walkthrough

Agent credential fixtures, assertions, and documentation now use opaque hmok_ access tokens while identifying credentials by their ac_ public ids. No runtime logic or public API declarations changed.

Changes

Agent credential token alignment

Layer / File(s)Summary
Token fixtures, assertions, and documentation
src/api/..., src/auth/..., src/commands/credentials.ts, src/storage/secrets.ts
Updated agent-auth and login test values to hmok_live_*, and clarified that persisted tokens are opaque hmok_ Bearer tokens distinct from ac_ public ids.

Estimated code review effort: 1 (Trivial) | ~3 minutes

Possibly related PRs

  • hookmyapp/cli#9: Related agent/auth.md login flow and agent-credential token handling updates.
  • hookmyapp/cli#14: Related OTP login tests and claim-completion token expectations.
  • hookmyapp/cli#21: Related agent-credential token and refresh-flow changes.

Suggested reviewers:ordvir

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 66.67% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title is specific, concise, and accurately reflects the main docstring terminology update in the PR.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ait-66-api-key-audit-nits

Comment @coderabbitai help to get the list of available commands.

@ord669
ord669 merged commit bc116be into mainJul 18, 2026
3 checks passed
@ord669
ord669 deleted the ait-66-api-key-audit-nits branch July 18, 2026 13:32
ord669 added a commit that referenced this pull request Aug 12, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ord669
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

AIT-66: correct stale ac_-Bearer-token docstrings - #26

Merged
ord669 merged 1 commit into
mainfrom
ait-66-api-key-audit-nits
Jul 18, 2026
Merged

AIT-66: correct stale ac_-Bearer-token docstrings#26
ord669 merged 1 commit into
mainfrom
ait-66-api-key-audit-nits

Conversation

@ord669

@ord669ord669 commented Jul 18, 2026

Copy link
Copy Markdown
Contributor

Refs AIT-66 (item 6 of the audit-nit batch; main fixes in hookmyapp/hookmyapp#108)

Docstring/fixture sweep only — no runtime changes:

  • Comments claiming keys are "ac_ Bearer tokens" corrected: the Bearer secret is an opaque hmok_ token; ac_ is the credential's public row id (see backend agent-token-prefix.ts).
  • Test fixtures renamed ac_live_*hmok_live_* so they model the real token shape.

19 affected tests green, tsc clean. (3 pre-existing cli-error-integration.test.ts failures reproduce on clean main — unrelated, tracked under AIT-171.)

Summary by CodeRabbit

  • Documentation

    • Clarified that agent access tokens are opaque hmok_… Bearer tokens.
    • Distinguished secret access tokens from their associated ac_ public credential IDs.
    • Updated authentication, credential management, logout, and credential storage guidance to reflect the current terminology.
  • Tests

    • Updated authentication and refresh scenarios to use the current access-token format.

…mok_, ac_ is the credential public id (AIT-66)
@coderabbitai

coderabbitaiBot commented Jul 18, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 8d00011f-3bdc-4a8d-b32f-1be5684f7033

📥 Commits

Reviewing files that changed from the base of the PR and between 60caee9 and a8ff399.

📒 Files selected for processing (8)
  • src/api/__tests__/agent-auth.test.ts
  • src/api/__tests__/agent-refresh.test.ts
  • src/api/agent-auth.ts
  • src/auth/__tests__/agentmd-login.test.ts
  • src/auth/login.ts
  • src/auth/logout.ts
  • src/commands/credentials.ts
  • src/storage/secrets.ts

📝 Walkthrough

Walkthrough

Agent credential fixtures, assertions, and documentation now use opaque hmok_ access tokens while identifying credentials by their ac_ public ids. No runtime logic or public API declarations changed.

Changes

Agent credential token alignment

Layer / File(s)Summary
Token fixtures, assertions, and documentation
src/api/..., src/auth/..., src/commands/credentials.ts, src/storage/secrets.ts
Updated agent-auth and login test values to hmok_live_*, and clarified that persisted tokens are opaque hmok_ Bearer tokens distinct from ac_ public ids.

Estimated code review effort: 1 (Trivial) | ~3 minutes

Possibly related PRs

  • hookmyapp/cli#9: Related agent/auth.md login flow and agent-credential token handling updates.
  • hookmyapp/cli#14: Related OTP login tests and claim-completion token expectations.
  • hookmyapp/cli#21: Related agent-credential token and refresh-flow changes.

Suggested reviewers:ordvir

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 66.67% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title is specific, concise, and accurately reflects the main docstring terminology update in the PR.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ait-66-api-key-audit-nits

Comment @coderabbitai help to get the list of available commands.

@ord669
ord669 merged commit bc116be into mainJul 18, 2026
3 checks passed
@ord669
ord669 deleted the ait-66-api-key-audit-nits branch July 18, 2026 13:32
ord669 added a commit that referenced this pull request Aug 12, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ord669
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

AIT-66: correct stale ac_-Bearer-token docstrings - #26

Merged
ord669 merged 1 commit into
mainfrom
ait-66-api-key-audit-nits
Jul 18, 2026
Merged

AIT-66: correct stale ac_-Bearer-token docstrings#26
ord669 merged 1 commit into
mainfrom
ait-66-api-key-audit-nits

Conversation

@ord669

@ord669ord669 commented Jul 18, 2026

Copy link
Copy Markdown
Contributor

Refs AIT-66 (item 6 of the audit-nit batch; main fixes in hookmyapp/hookmyapp#108)

Docstring/fixture sweep only — no runtime changes:

  • Comments claiming keys are "ac_ Bearer tokens" corrected: the Bearer secret is an opaque hmok_ token; ac_ is the credential's public row id (see backend agent-token-prefix.ts).
  • Test fixtures renamed ac_live_*hmok_live_* so they model the real token shape.

19 affected tests green, tsc clean. (3 pre-existing cli-error-integration.test.ts failures reproduce on clean main — unrelated, tracked under AIT-171.)

Summary by CodeRabbit

  • Documentation

    • Clarified that agent access tokens are opaque hmok_… Bearer tokens.
    • Distinguished secret access tokens from their associated ac_ public credential IDs.
    • Updated authentication, credential management, logout, and credential storage guidance to reflect the current terminology.
  • Tests

    • Updated authentication and refresh scenarios to use the current access-token format.

…mok_, ac_ is the credential public id (AIT-66)
@coderabbitai

coderabbitaiBot commented Jul 18, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 8d00011f-3bdc-4a8d-b32f-1be5684f7033

📥 Commits

Reviewing files that changed from the base of the PR and between 60caee9 and a8ff399.

📒 Files selected for processing (8)
  • src/api/__tests__/agent-auth.test.ts
  • src/api/__tests__/agent-refresh.test.ts
  • src/api/agent-auth.ts
  • src/auth/__tests__/agentmd-login.test.ts
  • src/auth/login.ts
  • src/auth/logout.ts
  • src/commands/credentials.ts
  • src/storage/secrets.ts

📝 Walkthrough

Walkthrough

Agent credential fixtures, assertions, and documentation now use opaque hmok_ access tokens while identifying credentials by their ac_ public ids. No runtime logic or public API declarations changed.

Changes

Agent credential token alignment

Layer / File(s)Summary
Token fixtures, assertions, and documentation
src/api/..., src/auth/..., src/commands/credentials.ts, src/storage/secrets.ts
Updated agent-auth and login test values to hmok_live_*, and clarified that persisted tokens are opaque hmok_ Bearer tokens distinct from ac_ public ids.

Estimated code review effort: 1 (Trivial) | ~3 minutes

Possibly related PRs

  • hookmyapp/cli#9: Related agent/auth.md login flow and agent-credential token handling updates.
  • hookmyapp/cli#14: Related OTP login tests and claim-completion token expectations.
  • hookmyapp/cli#21: Related agent-credential token and refresh-flow changes.

Suggested reviewers:ordvir

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 66.67% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title is specific, concise, and accurately reflects the main docstring terminology update in the PR.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ait-66-api-key-audit-nits

Comment @coderabbitai help to get the list of available commands.

@ord669
ord669 merged commit bc116be into mainJul 18, 2026
3 checks passed
@ord669
ord669 deleted the ait-66-api-key-audit-nits branch July 18, 2026 13:32
ord669 added a commit that referenced this pull request Aug 12, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ord669
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

AIT-66: correct stale ac_-Bearer-token docstrings - #26

Merged
ord669 merged 1 commit into
mainfrom
ait-66-api-key-audit-nits
Jul 18, 2026
Merged

AIT-66: correct stale ac_-Bearer-token docstrings#26
ord669 merged 1 commit into
mainfrom
ait-66-api-key-audit-nits

Conversation

@ord669

@ord669ord669 commented Jul 18, 2026

Copy link
Copy Markdown
Contributor

Refs AIT-66 (item 6 of the audit-nit batch; main fixes in hookmyapp/hookmyapp#108)

Docstring/fixture sweep only — no runtime changes:

  • Comments claiming keys are "ac_ Bearer tokens" corrected: the Bearer secret is an opaque hmok_ token; ac_ is the credential's public row id (see backend agent-token-prefix.ts).
  • Test fixtures renamed ac_live_*hmok_live_* so they model the real token shape.

19 affected tests green, tsc clean. (3 pre-existing cli-error-integration.test.ts failures reproduce on clean main — unrelated, tracked under AIT-171.)

Summary by CodeRabbit

  • Documentation

    • Clarified that agent access tokens are opaque hmok_… Bearer tokens.
    • Distinguished secret access tokens from their associated ac_ public credential IDs.
    • Updated authentication, credential management, logout, and credential storage guidance to reflect the current terminology.
  • Tests

    • Updated authentication and refresh scenarios to use the current access-token format.

…mok_, ac_ is the credential public id (AIT-66)
@coderabbitai

coderabbitaiBot commented Jul 18, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 8d00011f-3bdc-4a8d-b32f-1be5684f7033

📥 Commits

Reviewing files that changed from the base of the PR and between 60caee9 and a8ff399.

📒 Files selected for processing (8)
  • src/api/__tests__/agent-auth.test.ts
  • src/api/__tests__/agent-refresh.test.ts
  • src/api/agent-auth.ts
  • src/auth/__tests__/agentmd-login.test.ts
  • src/auth/login.ts
  • src/auth/logout.ts
  • src/commands/credentials.ts
  • src/storage/secrets.ts

📝 Walkthrough

Walkthrough

Agent credential fixtures, assertions, and documentation now use opaque hmok_ access tokens while identifying credentials by their ac_ public ids. No runtime logic or public API declarations changed.

Changes

Agent credential token alignment

Layer / File(s)Summary
Token fixtures, assertions, and documentation
src/api/..., src/auth/..., src/commands/credentials.ts, src/storage/secrets.ts
Updated agent-auth and login test values to hmok_live_*, and clarified that persisted tokens are opaque hmok_ Bearer tokens distinct from ac_ public ids.

Estimated code review effort: 1 (Trivial) | ~3 minutes

Possibly related PRs

  • hookmyapp/cli#9: Related agent/auth.md login flow and agent-credential token handling updates.
  • hookmyapp/cli#14: Related OTP login tests and claim-completion token expectations.
  • hookmyapp/cli#21: Related agent-credential token and refresh-flow changes.

Suggested reviewers:ordvir

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 66.67% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title is specific, concise, and accurately reflects the main docstring terminology update in the PR.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ait-66-api-key-audit-nits

Comment @coderabbitai help to get the list of available commands.

@ord669
ord669 merged commit bc116be into mainJul 18, 2026
3 checks passed
@ord669
ord669 deleted the ait-66-api-key-audit-nits branch July 18, 2026 13:32
ord669 added a commit that referenced this pull request Aug 12, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ord669
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

AIT-66: correct stale ac_-Bearer-token docstrings - #26

Merged
ord669 merged 1 commit into
mainfrom
ait-66-api-key-audit-nits
Jul 18, 2026
Merged

AIT-66: correct stale ac_-Bearer-token docstrings#26
ord669 merged 1 commit into
mainfrom
ait-66-api-key-audit-nits

Conversation

@ord669

@ord669ord669 commented Jul 18, 2026

Copy link
Copy Markdown
Contributor

Refs AIT-66 (item 6 of the audit-nit batch; main fixes in hookmyapp/hookmyapp#108)

Docstring/fixture sweep only — no runtime changes:

  • Comments claiming keys are "ac_ Bearer tokens" corrected: the Bearer secret is an opaque hmok_ token; ac_ is the credential's public row id (see backend agent-token-prefix.ts).
  • Test fixtures renamed ac_live_*hmok_live_* so they model the real token shape.

19 affected tests green, tsc clean. (3 pre-existing cli-error-integration.test.ts failures reproduce on clean main — unrelated, tracked under AIT-171.)

Summary by CodeRabbit

  • Documentation

    • Clarified that agent access tokens are opaque hmok_… Bearer tokens.
    • Distinguished secret access tokens from their associated ac_ public credential IDs.
    • Updated authentication, credential management, logout, and credential storage guidance to reflect the current terminology.
  • Tests

    • Updated authentication and refresh scenarios to use the current access-token format.

…mok_, ac_ is the credential public id (AIT-66)
@coderabbitai

coderabbitaiBot commented Jul 18, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 8d00011f-3bdc-4a8d-b32f-1be5684f7033

📥 Commits

Reviewing files that changed from the base of the PR and between 60caee9 and a8ff399.

📒 Files selected for processing (8)
  • src/api/__tests__/agent-auth.test.ts
  • src/api/__tests__/agent-refresh.test.ts
  • src/api/agent-auth.ts
  • src/auth/__tests__/agentmd-login.test.ts
  • src/auth/login.ts
  • src/auth/logout.ts
  • src/commands/credentials.ts
  • src/storage/secrets.ts

📝 Walkthrough

Walkthrough

Agent credential fixtures, assertions, and documentation now use opaque hmok_ access tokens while identifying credentials by their ac_ public ids. No runtime logic or public API declarations changed.

Changes

Agent credential token alignment

Layer / File(s)Summary
Token fixtures, assertions, and documentation
src/api/..., src/auth/..., src/commands/credentials.ts, src/storage/secrets.ts
Updated agent-auth and login test values to hmok_live_*, and clarified that persisted tokens are opaque hmok_ Bearer tokens distinct from ac_ public ids.

Estimated code review effort: 1 (Trivial) | ~3 minutes

Possibly related PRs

  • hookmyapp/cli#9: Related agent/auth.md login flow and agent-credential token handling updates.
  • hookmyapp/cli#14: Related OTP login tests and claim-completion token expectations.
  • hookmyapp/cli#21: Related agent-credential token and refresh-flow changes.

Suggested reviewers:ordvir

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 66.67% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title is specific, concise, and accurately reflects the main docstring terminology update in the PR.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ait-66-api-key-audit-nits

Comment @coderabbitai help to get the list of available commands.

@ord669
ord669 merged commit bc116be into mainJul 18, 2026
3 checks passed
@ord669
ord669 deleted the ait-66-api-key-audit-nits branch July 18, 2026 13:32
ord669 added a commit that referenced this pull request Aug 12, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ord669