mirror of
https://github.com/home-assistant/supervisor.git
synced 2026-09-29 12:28:34 +01:00
Since #6203 the set-options endpoint stores the value returned by the options validator. The validator replaces "!secret x" with the resolved secret before type-checking, so the plaintext secret ended up in the persisted app options instead of the reference (#7152). Make the validator non-destructive on request instead of restoring the references afterwards: AppOptions gains a resolve_secrets flag. When it is False, a "!secret x" value is still validated against the resolved secret (including the pwned hash and type coercion) but the reference is returned. The set-options endpoint validates with resolve_secrets=False, while write_options and the self options config endpoint keep resolving secrets for the container. Fixes #7152 Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>