You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Drop the v1 auth.json and unkeyed keyring migration paths #1480
TL;DR — Wrap up of our discussion, lets continue here until we find suitable solution.
Context
Raised in #1459 review. Stage-1 (#1383) moved auth to v2: profiles keyed by user ID, secrets keyed per profile. To keep old installs working, the CLI still carries v1 code:
Top-level token and proxy on AuthFile, plus LegacyAuthFile — auth-file.ts#L40-L57
Fixed-name keyring entries (legacyKeyringKey) and the code that moves them — credentials.ts#L44, ensureMigrated#L311, dropUnkeyedSecrets#L346, keyKeyringSecrets#L361, ensureSecretsKeyed#L424
Proposal (from the thread)
Watch the users-per-version telemetry dashboard. Remove the v1 code when 90–95% of users run a version that includes the migration. About 5% of users stay on old versions (some on deprecated Node), so 100% is not a realistic target.
Announce the removal before it ships (changelog, release notes), so users who skip the window know to run apify login again.
After removal, a user with a v1 file is logged out and must log in again. login and logout must still wipe v1 entries from auth.json and the keyring, so no plaintext secret stays behind.
Open questions
Q1: Remove at all, or keep the migration forever? Cost of keeping: the extra types, keyring reads on migration, and test surface. Cost of removing: a forced re-login for late upgraders.
Note
TL;DR — Wrap up of our discussion, lets continue here until we find suitable solution.
Context
Raised in #1459 review. Stage-1 (#1383) moved auth to v2: profiles keyed by user ID, secrets keyed per profile. To keep old installs working, the CLI still carries v1 code:
tokenandproxyonAuthFile, plusLegacyAuthFile—auth-file.ts#L40-L57toV2,MIGRATION_STEPS) —auth-file.ts#L123-L153auth-file.ts#L222-L225legacyKeyringKey) and the code that moves them —credentials.ts#L44,ensureMigrated#L311,dropUnkeyedSecrets#L346,keyKeyringSecrets#L361,ensureSecretsKeyed#L424Proposal (from the thread)
apify loginagain.loginandlogoutmust still wipe v1 entries fromauth.jsonand the keyring, so no plaintext secret stays behind.Open questions
logoutkeep thelegacyKeyringKeycleanup after the rest goes, as a cheap safety net?Done when
login/logoutstill clear any v1 leftovers🤖 Generated with Claude Code