mirror of
https://github.com/rmcrackan/Libation.git
synced 2026-09-13 14:17:15 -04:00
AudibleApi 11 holds token, key, and cookie values in a SecretString rather than a string, so nothing public exposes plaintext for a reflective logger to find. Picking it up is a breaking upgrade: the seven package references move, and the nine places that read a secret now call Reveal(). Two of those needed thought rather than a mechanical edit. Mkb79Auth exports to and imports from audible-cli's JSON format, which is plaintext by definition, so the cookie projections reveal explicitly in both directions and the file format is unchanged. And the account's own DecryptKey stays a plain string here: converting it is separate work. This is the dependency bump only. The log leak it enables fixing - an AuthenticationRequiredException carrying a live Account, whose address and activation bytes Serilog.Exceptions writes into a shared log - is still open, and none of the account-side masking has landed yet. Co-authored-by: rmcrackan <rmcrackan@gmail.com>
22 lines
575 B
XML
22 lines
575 B
XML
<Project Sdk="Microsoft.NET.Sdk">
|
|
|
|
<PropertyGroup>
|
|
<TargetFramework>net10.0</TargetFramework>
|
|
<Nullable>enable</Nullable>
|
|
</PropertyGroup>
|
|
|
|
<ItemGroup>
|
|
<PackageReference Include="Dinah.Core" Version="10.2.2.1" />
|
|
<PackageReference Include="Polly" Version="8.6.6" />
|
|
</ItemGroup>
|
|
|
|
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|AnyCPU'">
|
|
<DebugType>embedded</DebugType>
|
|
</PropertyGroup>
|
|
|
|
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|AnyCPU'">
|
|
<DebugType>embedded</DebugType>
|
|
</PropertyGroup>
|
|
|
|
</Project>
|