feat(config): wrap credentials in SecretStr (audit S-4)

database_url, migration_database_url, mcp_auth_token and the mathpix app
id/key are now pydantic SecretStr, so they render as '**********' in any
repr/log/traceback instead of leaking the plaintext credential. Consumers
(db.get_conn, cli.migrate, mcp._require_http_token, mathpix.extract_formulas)
call .get_secret_value() at the point of use. Tests updated to the SecretStr
type.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Tarik Moussa
2026-06-15 21:32:13 +02:00
parent e7b854db10
commit b4fbd7930e
8 changed files with 27 additions and 19 deletions

View File

@@ -36,7 +36,7 @@ def get_conn() -> Generator[psycopg.Connection[psycopg.rows.DictRow], None, None
"""
settings = get_settings()
with psycopg.connect(
settings.database_url,
settings.database_url.get_secret_value(),
row_factory=psycopg.rows.dict_row,
) as conn:
yield conn