Credential fields opt out of browser autofill; body-key adapters are not "Public API" - #840
Merged
Merged
Conversation
…not "Public API" Found while testing the install form in a real browser: Chrome filled the Odoo 14-18 form's "ODOO UID" with the signed-in user's e-mail and "ODOO API KEY" with their saved AnythingMCP password. A text field followed by a password field reads as a login form. The same happens on a connector's Basic Auth / login-token / OAuth editor, and it matches two live cases: a BuchhaltungsButler connector whose Basic Auth held the user's login e-mail and password, and an Odoo connector whose database held the user's e-mail. - Install form: every variable gets a non-login name, autocomplete "off" (or "new-password" for secrets) and the opt-out attributes of 1Password, LastPass, Bitwarden and Dashlane. - Connector page: the same on the auth editor's username / client id and password / secret / token fields that had none. - Marketplace chip: an adapter with authType NONE that still requires a key/token/secret/password variable (Odoo's JSON-RPC, Telegram, Bluesky, ...) is labelled "API Key", not "Public API".
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Found while testing the cloud install form in a real browser: Chrome filled the Odoo 14-18 form's ODOO UID with the signed-in user's e-mail and ODOO API KEY with their saved AnythingMCP password (a text field followed by a password field reads as a login form). It matches two live cases from the connector audit: a BuchhaltungsButler connector whose Basic Auth held the user's login e-mail and password, and an Odoo connector whose database field held the user's e-mail.
connectors/store): each variable input getsname=amcp-connector-var-<VAR>,autoCompleteoff/new-password, anddata-1p-ignore,data-lpignore,data-bwignore,data-form-type=other.autoCompleteget the same treatment (env vars and headers editors already had it).adapterAuthLabel/adapterNeedsCredentialsshow "API Key" (lock, neutral) instead of "Public API" whenauthTypeis NONE but a key/token/secret/password variable is required (odoo-jsonrpc, telegram-bot, bluesky, odds-api, ...). Same rule asadapter-count.mjs's keyless count since Catalog audit: fix the #642 adapters against the vendors' real APIs #833.Test: new
install-form-no-autofill.spec.ts(chip label, autocomplete/name/opt-out attributes on the install form); connector env-vars/OAuth1 edit and starter-pack e2e still green; typecheck clean.