Skip to content

Purge hardcoded live API keys from account defaults #1160

Description

@greatest0fallt1me

Summary

useAccountContext.tsx ships DEFAULT_ACCOUNTS containing apiKey values like 'ck_live_4e85ff1ed6a4ff73893a0bf73f2bb' and seeds them into localStorage for every new visitor.

Why this matters

Anything in the bundle is public; strings shaped like live keys invite abuse if real, and train code review to ignore secret-looking literals. SecureErrorHandler even has a pattern specifically for ck_live_ keys.

Scope

Remove apiKey from DEFAULT_ACCOUNTS (or the seeding altogether), load accounts from the backend after authentication, and use obviously fake placeholders in tests only. Rotate the keys server-side if they were ever real.

Relevant code in CalloraOrg/Callora-Frontend:

  • src/hooks/useAccountContext.tsx
  • src/state/accountStore.ts

Priority

High

Acceptance criteria

  • No ck_live_ literal remains in src outside tests
  • New visitors are not seeded with API keys
  • Account data is loaded from an authenticated source
  • Tests use clearly fake keys

Validation

grep -rn ck_live_ src --include=.ts --include=.tsx | grep -v test is empty; npm test -- --run

Non-goals

  • Typo-only, formatting-only, or cosmetic changes.
  • Unrelated refactors, dependency upgrades, or broad rewrites.
  • Removing safeguards or weakening validation to make tests pass.

Contributor application

Before coding, describe the affected modules, proposed state/invariant changes, test strategy, compatibility considerations, and an estimate. Wait for assignment before starting implementation.

PR requirements

Use a feature branch and include Closes #<issue-number>. Address every criterion, map criteria to code and tests, explain security and failure-mode handling, and ensure CI passes.

Quality review

A maintainer will assess correctness, completeness, test depth, compatibility, observability, and adverse-case handling. A substantive implementation is required; merge or CI status alone does not guarantee reward eligibility.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Stellar WaveStellar Wave Program issue

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions