fix(site): show when secret deployment options are configured (#22151)

Previously, when secret deployment options like CODER_OIDC_CLIENT_SECRET
were populated, the API correctly returned the "secret": "true"
annotation, but the UI did not indicate that these secrets were
configured. The UI would show "Not set" regardless of whether the secret
was set or not.

Now, the UI checks both the secret annotation and the value_source
field. When a secret is configured (value_source is set), it displays
"Set" to indicate the secret is populated. When a secret is not
configured, it displays "Not set".

Fixes #18913

Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>
This commit is contained in:
Jeremy Ruppel
2026-02-20 15:42:28 -05:00
committed by GitHub
co-authored by Claude Sonnet 4.5
parent e6f0a1b2f6
commit de4ff78cd1
3 changed files with 44 additions and 0 deletions
@@ -26,6 +26,17 @@ const meta: Meta<typeof UserAuthSettingsPageView> = {
flag_shorthand: "o",
hidden: false,
},
{
name: "OIDC Client Secret",
description: "Client secret to use for Login with OIDC.",
value: "",
value_source: "env",
env: "CODER_OIDC_CLIENT_SECRET",
group: oidcGroup,
flag: "oidc-client-secret",
annotations: { secret: "true" },
hidden: false,
},
{
name: "OIDC Allow Signups",
description: "Whether new users can sign up with OIDC.",
@@ -72,6 +83,16 @@ const meta: Meta<typeof UserAuthSettingsPageView> = {
flag_shorthand: "o",
hidden: false,
},
{
name: "OAuth2 GitHub Client Secret",
description: "Client secret for Login with GitHub.",
value: "",
value_source: "flag",
group: ghGroup,
flag: "oauth2-github-client-secret",
annotations: { secret: "true" },
hidden: false,
},
{
name: "OAuth2 GitHub Allow Signups",
description: "Whether new users can sign up with GitHub.",
@@ -147,6 +147,25 @@ describe("optionValue", () => {
},
expected: 30000000000,
},
{
option: {
...defaultOption,
name: "OIDC Client Secret Is Set",
value: "",
value_source: "env",
annotations: { secret: "true" },
},
expected: "Set",
},
{
option: {
...defaultOption,
name: "OIDC Client Secret Is Not Set",
value: "",
annotations: { secret: "true" },
},
expected: "",
},
])(
"[$option.name]optionValue($option.value)",
({ option, expected, additionalValues }) => {
@@ -13,6 +13,10 @@ export function optionValue(
continue; // skip if not explicitly true
}
switch (k) {
case "secret":
// For secret fields, show "Set" if configured, otherwise show empty
// (which will be rendered as "Not set" by OptionValue component)
return option.value_source ? "Set" : "";
case "format_duration":
return humanDuration((option.value as number) / 1e6);
// Add additional cases here as needed.