Repository navigation
fix(run): fetch every secret without --only, and clear the spinner on --json errors - #61
Merged
Merged
Conversation
Since b703cb2, `stashbase run -p <project> -e <env> -- cmd` without --only skipped the secrets request and started the command with no secrets: an empty --only was read as "nothing left to fetch" instead of "every secret". An agent run still fetches only the secrets its profile binds, so an empty binding list there still means none. The "Egress-only profile" wording is now limited to agent runs; plain run always says "Environment loaded (N secrets)".
With --json, the "no secrets found" error was printed after the spinner
frame on the same line ("Loading environment...{"), so the output was
not clean JSON.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
runwithout--onlystarted the command with no secrets. Since b703cb2,stashbase run -p <project> -e <env> -- cmdskipped the secrets request: an empty--onlywas read as "nothing left to fetch" instead of "every secret". It printed "Egress-only profile (0 secrets)" and exited 0. Plainrunnow fetches every secret again. An agent run still fetches only the secrets its profile binds, so an empty binding list there still means none. That's important: otherwise an agent could receive the whole environment.runnow always printsEnvironment loaded (N secrets).--jsonerrors no longer get glued to the spinner. The "no secrets found" error was printed after the spinner frame (Loading environment...{), so the output wasn't clean JSON. The spinner is now cleared first, as in the text output and inpull.Test plan
runwithout--onlyattempts the fetch and doesn't start the command when it fails (fails on master: the child ran and exited 0)--jsonerror doesn't follow the spinner frame on the same line--jsonspinner bug by hand before the fix and confirmed it aftercargo fmt --checkandcargo testpass