Env-plant: recognize a Settings-connected credential's provider - #436
Merged
TheGreatAxios merged 3 commits intoAug 29, 2026
Merged
TheGreatAxios merged 3 commits into
TheGreatAxios merged 3 commits into
Conversation
A tenant that connects a provider in Settings names the credential
after the connector's displayName ("Anthropic"), not this module's
own "anthropic-default" convention, so the existing name-only match
misses it. Covers the case: an active credential named "Anthropic"
under the same provider must stop the env-plant from probing or
creating a second row.
plantEnvProviderCredentials matched an existing plant only by the
literal name inferenceCredentialName(provider) ("anthropic-default"),
but a Settings-connected credential is named after the connector's
displayName ("Anthropic") instead. A tenant that connected Anthropic
in Settings, on a hub booted with ANTHROPIC_API_KEY, never matched -
a live probe call and a second credential row got planted on every
boot. Match on the provider row (providerId) both paths key their
credential to, resolved read-only so a provider nobody has connected
yet isn't planted just to check.
Fixes CL-7128.
…entials findProviderId read only page one of the providers list, unlike its sibling findActiveCredential, so a match on a later page was missed. The active-credential match also ignored credential type, so a non-inference row on the same provider could be mistaken for the plant. Paginate findProviderId the same way, and restrict the match to the types seedCatalog itself ever writes for an inference source (api_key, oauth_token).
TheGreatAxios
force-pushed
the
cl-7128-env-key-auto-plant-cannot-see-a-settings-connected
branch
from
August 29, 2026 04:46
c42a534 to
2573f16
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes CL-7128 — https://linear.app/abklabs/issue/CL-7128
Problem
persistConnectorCredential(packages/connections/src/persist-credential.ts:117-138) names a Settings-connected credential after the connector'sdisplayName("Anthropic").plantEnvProviderCredentials(packages/onboarding/src/plant-env-credentials.ts,findActiveCredential) checked for an existing plant only by matchinginferenceCredentialName(provider)("anthropic-default",packages/hub-client/src/seed.ts:998). A tenant that connected Anthropic in Settings, on a hub booted withANTHROPIC_API_KEY, never matched that name — so every boot ran a live probe call to Anthropic and planted a second, redundant credential row.Change
findProviderId: a read-only lookup of the provider row a curated provider's connections (env-plant and a Settings connect alike) both key their credential to (ensureProvider's own{ name: provider }pair). It never creates the row, so a provider nobody has connected yet still reads back as "no active credential."findActiveCredentialnow matches onproviderIdinstead of the credential's ownname, so it recognizes either naming convention.persistConnectorCredentialandplantEnvProviderCredentialsstill name their rows exactly as before.Tests
Extended
packages/onboarding/test/plant-env-credentials.test.ts: a new red/green case plants an active credential named "Anthropic" under the same provider and asserts booting with the env key makes no probe call and creates no second row. All 23 tests in the file pass, andbunx tsc --noEmit -p packages/onboardingis clean.Note: the machine was under heavy load while this PR was prepared, so the full local
bun run checkgate was skipped (it was OOM-killed) — CI is the gate for this PR.