feat: add enable/disable support for user secrets (#27537)

Users can now disable a secret to stop it from being injected into
workspaces without deleting it, and re-enable it later. Disabled secrets
stay visible and editable everywhere they already appear.

An enabled secret must have at least one injection target; a secret with
no target can be stored only while disabled. Existing target-less secrets
are migrated to disabled to preserve current behavior.

Support spans the REST API, SDK, CLI, dashboard, and audit log.
This commit is contained in:
Zach
2026-07-28 09:58:33 -06:00
committed by GitHub
parent 3c61a9a939
commit 85984ff142
56 changed files with 1391 additions and 186 deletions
+6 -3
View File
@@ -13,7 +13,7 @@ WHERE id = @id;
-- REST API list and get endpoints.
SELECT
id, user_id, name, description,
env_name, file_path,
env_name, file_path, enabled,
created_at, updated_at
FROM user_secrets
WHERE user_id = @user_id
@@ -37,7 +37,8 @@ INSERT INTO user_secrets (
value,
value_key_id,
env_name,
file_path
file_path,
enabled
) VALUES (
@id,
@user_id,
@@ -46,7 +47,8 @@ INSERT INTO user_secrets (
@value,
@value_key_id,
@env_name,
@file_path
@file_path,
@enabled
) RETURNING *;
-- name: UpdateUserSecretByUserIDAndName :one
@@ -57,6 +59,7 @@ SET
description = CASE WHEN @update_description::bool THEN @description ELSE description END,
env_name = CASE WHEN @update_env_name::bool THEN @env_name ELSE env_name END,
file_path = CASE WHEN @update_file_path::bool THEN @file_path ELSE file_path END,
enabled = CASE WHEN @update_enabled::bool THEN @enabled ELSE enabled END,
updated_at = CURRENT_TIMESTAMP
WHERE user_id = @user_id AND name = @name
RETURNING *;