From ba4503cdd9acd4017b27b29607c9a9287d8196d0 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Andr=C3=A9=20Padez?= Date: Wed, 29 Jul 2026 03:13:16 +0000 Subject: [PATCH] vault: remove temp connect/token diagnostic log The crypto-shape question is answered (classic + v2 fields both present); drop the diagnostic that logged the response field names. Co-Authored-By: Claude Opus 4.8 --- src/servers/api/vault/router.ts | 7 ------- 1 file changed, 7 deletions(-) diff --git a/src/servers/api/vault/router.ts b/src/servers/api/vault/router.ts index b3833069..ded3b1d8 100644 --- a/src/servers/api/vault/router.ts +++ b/src/servers/api/vault/router.ts @@ -83,13 +83,6 @@ vaultRouter.post('/session/login', async (ctx) => { clientId, }); - // TEMP diagnostic — field NAMES only (values redacted) to empirically confirm the crypto shape. - const names = (o: unknown) => (o && typeof o === 'object' ? Object.keys(o as object) : typeof o); - const udo = (d as { UserDecryptionOptions?: { MasterPasswordUnlock?: unknown } }).UserDecryptionOptions; - console.log( - `[vault] connect/token fields: ${Object.keys(d).join(',')} | UserDecryptionOptions=${JSON.stringify(names(udo))} | MasterPasswordUnlock=${JSON.stringify(names(udo?.MasterPasswordUnlock))} | AccountKeys=${JSON.stringify(names((d as { AccountKeys?: unknown }).AccountKeys))}`, - ); - // Everything except the transport tokens (which the platform holds) is crypto material the SDK unlocks // on-device — ciphertext to us. Vaultwarden returns BOTH classic (Key/PrivateKey/Kdf*) and v2 // (UserDecryptionOptions.MasterPasswordUnlock, AccountKeys); pass the whole native response through