[PR #24800] replace the secret field from obfuscated to full-masked value #30792

Closed
opened 2026-02-21 20:48:14 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/24800

State: closed
Merged: Yes


Summary

Fixes #24660
I believe that secret variables should replace all characters with asterisks, rather than showing part of them. obfuscation can be use to mask the user name but it's not good idea for handle the password. the uncovered characters may reveal patterns in the password.

Screenshots

Before After
image image

Checklist

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran dev/reformat(backend) and cd web && npx lint-staged(frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/24800 **State:** closed **Merged:** Yes --- ## Summary Fixes #24660 I believe that secret variables should replace all characters with asterisks, rather than showing part of them. obfuscation can be use to mask the user name but it's not good idea for handle the password. the uncovered characters may reveal patterns in the password. ## Screenshots | Before | After | |--------|-------| | <img width="410" height="275" alt="image" src="https://github.com/user-attachments/assets/9f6509ac-9d90-4e1f-ba66-4b24429b2256" /> | <img width="411" height="276" alt="image" src="https://github.com/user-attachments/assets/136f2211-32bc-45cd-b85d-59105b5c503c" /> | ## Checklist - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `dev/reformat`(backend) and `cd web && npx lint-staged`(frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:48:14 -05:00
yindo closed this issue 2026-02-21 20:48:14 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#30792