Skip to content

fix(run): fetch every secret without --only, and clear the spinner on --json errors - #61

Merged
radim10 merged 2 commits into
masterfrom
fix/run-fetch-all-secrets
Oct 8, 2026
Merged

radim10 merged 2 commits into
masterfrom
fix/run-fetch-all-secrets

Conversation

@radim10

@radim10 radim10 commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

Summary

  • run without --only started the command with no secrets. Since b703cb2, stashbase run -p <project> -e <env> -- cmd skipped the secrets request: an empty --only was read as "nothing left to fetch" instead of "every secret". It printed "Egress-only profile (0 secrets)" and exited 0. Plain run now fetches every secret again. An agent run still fetches only the secrets its profile binds, so an empty binding list there still means none. That's important: otherwise an agent could receive the whole environment.
  • "Egress-only profile" is agent-only wording. Plain run now always prints Environment loaded (N secrets).
  • --json errors no longer get glued to the spinner. The "no secrets found" error was printed after the spinner frame (Loading environment...{), so the output wasn't clean JSON. The spinner is now cleared first, as in the text output and in pull.

Test plan

  • New integration test: run without --only attempts the fetch and doesn't start the command when it fails (fails on master: the child ran and exited 0)
  • New integration test: a --json error doesn't follow the spinner frame on the same line
  • Unit tests for the fetch decision (plain run, agent run, local file covering every requested secret) and for the loaded message
  • Reproduced the --json spinner bug by hand before the fix and confirmed it after
  • cargo fmt --check and cargo test pass
  • Checked by hand against the staging API: a fetched secret reaches the child process

Since b703cb2, `stashbase run -p <project> -e <env> -- cmd` without
--only skipped the secrets request and started the command with no
secrets: an empty --only was read as "nothing left to fetch" instead of
"every secret". An agent run still fetches only the secrets its profile
binds, so an empty binding list there still means none.

The "Egress-only profile" wording is now limited to agent runs; plain
run always says "Environment loaded (N secrets)".
With --json, the "no secrets found" error was printed after the spinner
frame on the same line ("Loading environment...{"), so the output was
not clean JSON.
@radim10 radim10 self-assigned this Oct 8, 2026
@radim10
radim10 merged commit 37b6a7c into master Oct 8, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant