Skip to content

Preserve saved credentials when decryption or Keychain fails #7

Description

@ratovarius

Workflow improvement

Preserve saved credentials when decryption or Keychain fails.

Proposed implementation

Stop deleting credentials.enc and token_cache.json when credential decryption or keyring access fails. Return a clear authentication error with safe remediation; preserve original files and do not silently fall back to ADC or another user when explicit encrypted credentials exist but fail. Limit change to failure handling; keep precedence and deliberate logout unchanged. Make explicit credentials-file behavior consistent with documented precedence without broad unrelated auth redesign. Avoid expanding googleworkspace#891 profile/backend policy: fix data preservation for default and configured directories. Extract testable failure path/dependency where necessary rather than hitting OS keychain in unit tests. Tests with fake encrypted bytes and file-backed test key/config only; never real credentials.

Acceptance criteria and tests

Decryption failure leaves credential/token sentinels unchanged; keyring acquisition failure preservation; explicit/default config contexts; error explains decrypt/keyring failure without secret bytes; no ADC fallback on existing broken credential file; absence still permits original fallback; explicit logout still deletes through its intentional path; repeated failure is repeatable and nondestructive. Isolate environment and restore variables.

Upstream coordination

Related: googleworkspace#886; prior closed PR googleworkspace#891.

This fork issue tracks one independent contribution from our document-workflow improvement effort. Existing upstream issues remain the canonical reports; the resulting PR will target googleworkspace/cli and reference them.

Delivery

  • Separate branch: fix/preserve-credentials.
  • Tests first, independent code review, required checks and changeset.
  • Synthetic fixtures only; no personal documents or credentials in public artifacts.

Implementation PR: googleworkspace#937

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions