Skip to content

Credential fields opt out of browser autofill; body-key adapters are not "Public API" - #840

Merged
keysersoft merged 1 commit into
mainfrom
keysersoft/no-credential-autofill
Oct 3, 2026
Merged

keysersoft merged 1 commit into
mainfrom
keysersoft/no-credential-autofill

Conversation

@keysersoft

Copy link
Copy Markdown
Contributor

Found while testing the cloud install form in a real browser: Chrome filled the Odoo 14-18 form's ODOO UID with the signed-in user's e-mail and ODOO API KEY with their saved AnythingMCP password (a text field followed by a password field reads as a login form). It matches two live cases from the connector audit: a BuchhaltungsButler connector whose Basic Auth held the user's login e-mail and password, and an Odoo connector whose database field held the user's e-mail.

  • Install form (connectors/store): each variable input gets name=amcp-connector-var-<VAR>, autoComplete off / new-password, and data-1p-ignore, data-lpignore, data-bwignore, data-form-type=other.
  • Connector page auth editor: the 5 password inputs and 4 username/client-id inputs without autoComplete get the same treatment (env vars and headers editors already had it).
  • Marketplace chip: adapterAuthLabel / adapterNeedsCredentials show "API Key" (lock, neutral) instead of "Public API" when authType is NONE but a key/token/secret/password variable is required (odoo-jsonrpc, telegram-bot, bluesky, odds-api, ...). Same rule as adapter-count.mjs's keyless count since Catalog audit: fix the #642 adapters against the vendors' real APIs #833.

Test: new install-form-no-autofill.spec.ts (chip label, autocomplete/name/opt-out attributes on the install form); connector env-vars/OAuth1 edit and starter-pack e2e still green; typecheck clean.

…not "Public API"

Found while testing the install form in a real browser: Chrome filled the
Odoo 14-18 form's "ODOO UID" with the signed-in user's e-mail and
"ODOO API KEY" with their saved AnythingMCP password. A text field followed
by a password field reads as a login form. The same happens on a
connector's Basic Auth / login-token / OAuth editor, and it matches two live
cases: a BuchhaltungsButler connector whose Basic Auth held the user's
login e-mail and password, and an Odoo connector whose database held the
user's e-mail.

- Install form: every variable gets a non-login name, autocomplete "off"
  (or "new-password" for secrets) and the opt-out attributes of 1Password,
  LastPass, Bitwarden and Dashlane.
- Connector page: the same on the auth editor's username / client id and
  password / secret / token fields that had none.
- Marketplace chip: an adapter with authType NONE that still requires a
  key/token/secret/password variable (Odoo's JSON-RPC, Telegram, Bluesky,
  ...) is labelled "API Key", not "Public API".
@keysersoft
keysersoft merged commit d7a08df into main Oct 3, 2026
14 checks passed
@keysersoft
keysersoft deleted the keysersoft/no-credential-autofill branch October 3, 2026 12:23
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 3, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant