Skip to content

Preserve proxy credentials during allowed-domain updates - #256

Merged
bbrowning merged 3 commits into
mainfrom
preserve-proxy-credentials
Aug 31, 2026
Merged

bbrowning merged 3 commits into
mainfrom
preserve-proxy-credentials

Conversation

@bbrowning

Copy link
Copy Markdown
Owner

Prevent paude allowed-domains from dropping active proxy credentials when rebuilding a session proxy.

  • Preserve existing Podman and Docker credential bindings by default
  • Add explicit credential refresh support
  • Roll back when a replacement proxy fails to start or remain running
  • Persist allowed-domain changes across recovery and upgrades
  • Keep Cursor browser OAuth working without CURSOR_API_KEY

Preserve current Podman secret bindings and Docker credential values
when domain-only changes recreate the proxy. Add explicit credential
refresh, atomic durable domain state, and rollback ordering so failed
replacements leave the working proxy intact.

Document the behavior and cover inspection, refresh, recovery, and
failure paths across both backends.
Separate credentials that can be supplied from those required by the
active provider mode. This lets Cursor browser OAuth update domains
without CURSOR_API_KEY.

Inspect each replacement after initialization. If it has stopped, roll
back and preserve the retained working proxy.
Run every pytest Make target with one explicit color environment and
centralize ANSI normalization for rendered CLI assertions.

Cover the Make child environment and shared normalizer so inherited
terminal settings cannot mask styling-sensitive tests.
@bbrowning
bbrowning merged commit 4d493d9 into main Aug 31, 2026
5 checks passed
@bbrowning
bbrowning deleted the preserve-proxy-credentials branch August 31, 2026 18:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant