Files
supervisor/tests/api
Stefan AgnerandClaude Fable 5.1 64ea3be432 Keep "!secret" references when persisting app options (#7237)
Since #6203 the set-options endpoint stores the value returned by the
options validator. The validator replaces "!secret x" with the resolved
secret before type-checking, so the plaintext secret ended up in the
persisted app options instead of the reference (#7152).

Make the validator non-destructive on request instead of restoring the
references afterwards: AppOptions gains a resolve_secrets flag. When it
is False, a "!secret x" value is still validated against the resolved
secret (including the pwned hash and type coercion) but the reference is
returned. The set-options endpoint validates with resolve_secrets=False,
while write_options and the self options config endpoint keep resolving
secrets for the container.

Fixes #7152

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-17 15:27:39 +02:00
..