mirror of
https://github.com/rmcrackan/Libation.git
synced 2026-09-12 21:57:19 -04:00
AudibleApi 11 holds token, key, and cookie values in a SecretString rather than a string, so nothing public exposes plaintext for a reflective logger to find. Picking it up is a breaking upgrade: the seven package references move, and the nine places that read a secret now call Reveal(). Two of those needed thought rather than a mechanical edit. Mkb79Auth exports to and imports from audible-cli's JSON format, which is plaintext by definition, so the cookie projections reveal explicitly in both directions and the file format is unchanged. And the account's own DecryptKey stays a plain string here: converting it is separate work. This is the dependency bump only. The log leak it enables fixing - an AuthenticationRequiredException carrying a live Account, whose address and activation bytes Serilog.Exceptions writes into a shared log - is still open, and none of the account-side masking has landed yet. Co-authored-by: rmcrackan <rmcrackan@gmail.com>