mirror of
https://github.com/simstudioai/sim.git
synced 2026-09-24 15:45:35 +08:00
feat(secrets): let workspace secrets opt out of redaction (#7045)
* feat(secrets): let workspace secrets opt out of redaction * fix(secrets): certify no sandbox exemptions once the registry is incomplete * feat(secrets): carry visible secret values on the v2 list and document visibility * fix(secrets): read visible values by own property so prototype-named secrets cannot poison the list
This commit is contained in:
@@ -119,12 +119,27 @@ Click **Details** on any secret row to open its detail view.
|
||||
From here you can:
|
||||
|
||||
- View the **Key** and edit the **Value**
|
||||
- Toggle **Visibility** — show the value unmasked in run output; see [Visibility](#visibility)
|
||||
- Edit the **Description** — an optional note telling teammates what the secret is for. Workspace secrets only; a personal secret is not shared, so it has none
|
||||
- Manage **Members** — invite teammates by email and assign them an **Admin** or **Member** role
|
||||
- Open **See usage** — where this secret has actually been used
|
||||
|
||||
Click **Save** to apply changes, or **Back** to return to the list.
|
||||
|
||||
### Visibility
|
||||
|
||||
By default, a secret's resolved value is masked everywhere Sim shows run output (see [Execution log protection](#execution-log-protection)). For values that aren't actually sensitive — a staging key, a shared base URL — that masking makes your own logs harder to read.
|
||||
|
||||
**Show value in logs and Chat** turns masking off for one workspace secret. With it on:
|
||||
|
||||
- Run logs, Chat, and code output show the real value instead of `{{KEY}}`
|
||||
- Files a run writes with the value in them stay readable and attachable
|
||||
- The Secrets API list includes the value for this secret, so external agents can read it directly instead of scraping logs
|
||||
|
||||
The value becomes visible to **anyone who can see this workspace's runs** — including publicly shared log links and log exports, and regardless of member restrictions on the secret itself. Only turn it on for values you'd be comfortable printing in a log.
|
||||
|
||||
The switch applies to future runs only. Logs written while the secret was masked stay masked, and anything written while it was visible keeps the value even if you turn masking back on. If another secret holds the same value, that value stays masked — masking always wins a conflict. Workspace secrets only; the same people who can edit the description can flip it.
|
||||
|
||||
### See usage
|
||||
|
||||
**See usage** lists the runs that resolved this secret: when it was last used, what used it (a workflow, the Sim agent, or an MCP server), how it was triggered, who it resolved under, and a link to the most recent run in Logs. Rows are grouped by day, so a workflow on a schedule reads as one row per day rather than thousands.
|
||||
|
||||
Reference in New Issue
Block a user