Workflow improvement
Preserve saved credentials when decryption or Keychain fails.
Proposed implementation
Stop deleting credentials.enc and token_cache.json when credential decryption or keyring access fails. Return a clear authentication error with safe remediation; preserve original files and do not silently fall back to ADC or another user when explicit encrypted credentials exist but fail. Limit change to failure handling; keep precedence and deliberate logout unchanged. Make explicit credentials-file behavior consistent with documented precedence without broad unrelated auth redesign. Avoid expanding googleworkspace#891 profile/backend policy: fix data preservation for default and configured directories. Extract testable failure path/dependency where necessary rather than hitting OS keychain in unit tests. Tests with fake encrypted bytes and file-backed test key/config only; never real credentials.
Acceptance criteria and tests
Decryption failure leaves credential/token sentinels unchanged; keyring acquisition failure preservation; explicit/default config contexts; error explains decrypt/keyring failure without secret bytes; no ADC fallback on existing broken credential file; absence still permits original fallback; explicit logout still deletes through its intentional path; repeated failure is repeatable and nondestructive. Isolate environment and restore variables.
Upstream coordination
Related: googleworkspace#886; prior closed PR googleworkspace#891.
This fork issue tracks one independent contribution from our document-workflow improvement effort. Existing upstream issues remain the canonical reports; the resulting PR will target googleworkspace/cli and reference them.
Delivery
- Separate branch:
fix/preserve-credentials.
- Tests first, independent code review, required checks and changeset.
- Synthetic fixtures only; no personal documents or credentials in public artifacts.
Implementation PR: googleworkspace#937
Workflow improvement
Preserve saved credentials when decryption or Keychain fails.
Proposed implementation
Stop deleting credentials.enc and token_cache.json when credential decryption or keyring access fails. Return a clear authentication error with safe remediation; preserve original files and do not silently fall back to ADC or another user when explicit encrypted credentials exist but fail. Limit change to failure handling; keep precedence and deliberate logout unchanged. Make explicit credentials-file behavior consistent with documented precedence without broad unrelated auth redesign. Avoid expanding googleworkspace#891 profile/backend policy: fix data preservation for default and configured directories. Extract testable failure path/dependency where necessary rather than hitting OS keychain in unit tests. Tests with fake encrypted bytes and file-backed test key/config only; never real credentials.
Acceptance criteria and tests
Decryption failure leaves credential/token sentinels unchanged; keyring acquisition failure preservation; explicit/default config contexts; error explains decrypt/keyring failure without secret bytes; no ADC fallback on existing broken credential file; absence still permits original fallback; explicit logout still deletes through its intentional path; repeated failure is repeatable and nondestructive. Isolate environment and restore variables.
Upstream coordination
Related: googleworkspace#886; prior closed PR googleworkspace#891.
This fork issue tracks one independent contribution from our document-workflow improvement effort. Existing upstream issues remain the canonical reports; the resulting PR will target googleworkspace/cli and reference them.
Delivery
fix/preserve-credentials.Implementation PR: googleworkspace#937