fix(forms): prevent browser autofill for API key fields

This commit is contained in:
LTbinglingfeng
2026-06-01 00:01:35 +08:00
parent 97b2152a81
commit 7c18e4c937
3 changed files with 19 additions and 2 deletions
@@ -152,6 +152,10 @@ export function AmpcodeForm({
onChange={(e) =>
setForm((s) => ({ ...s, upstreamApiKey: e.target.value }))
}
autoComplete="new-password"
data-1p-ignore="true"
data-lpignore="true"
data-bwignore="true"
disabled={mutating}
/>
</div>
@@ -127,8 +127,11 @@ function buildInitialForm(
const disabled = hasDisableAllModelsRule(cfg.excludedModels);
const excludedList = stripDisableAllRule(cfg.excludedModels);
return {
// Populate apiKey from resource.raw in edit mode so the field is not empty
apiKey: cfg.apiKey ?? '',
// Keep the API key blank in edit mode. Pre-filling the real key makes this
// password field a browser-autofill target (the saved management key can
// overwrite it) and defeats the "leave empty = keep unchanged" contract; an
// empty field is preserved on save via buildProviderKeyConfig's existing fallback.
apiKey: '',
name: '',
baseUrl: cfg.baseUrl ?? '',
proxyUrl: cfg.proxyUrl ?? '',
@@ -489,6 +492,10 @@ export function BaseProviderForm({
type={showSingleApiKey ? 'text' : 'password'}
value={form.apiKey}
onChange={(e) => updateField('apiKey', e.target.value)}
autoComplete="new-password"
data-1p-ignore="true"
data-lpignore="true"
data-bwignore="true"
placeholder={
mode === 'edit'
? t('providersPage.form.apiKeyEditPlaceholder')
@@ -769,6 +776,10 @@ export function BaseProviderForm({
)
)
}
autoComplete="new-password"
data-1p-ignore="true"
data-lpignore="true"
data-bwignore="true"
disabled={mutating}
placeholder={t('providersPage.form.apiKeyCreatePlaceholder')}
/>
+2
View File
@@ -272,6 +272,8 @@ export function LoginPage() {
label={t('login.management_key_label')}
placeholder={t('login.management_key_placeholder')}
type={showKey ? 'text' : 'password'}
name="cpa-management-key"
autoComplete="current-password"
value={managementKey}
onChange={(e) => setManagementKey(e.target.value)}
onKeyDown={handleSubmitKeyDown}