fix: use placeholder for stored sso client secret instead of a masked value

The client secret input rendered a string of asterisks as the input's value whenever a secret
was already stored. Because the input is controlled, clicking into the field and pasting a new
secret without selecting all appended it to the asterisks, and the submit path stored the
concatenated string, breaking SSO login for the organisation.

Render the field empty and show the dots as a placeholder instead, so pasting replaces cleanly.
The placeholder only appears while the form value is null (stored secret untouched), so a fresh
portal or a cleared field renders empty rather than suggesting a secret is still being kept.

Fixes #3183
This commit is contained in:
Catalin Pit
2026-10-01 15:36:04 +01:00
parent 8a41a3bf61
commit 6e94e39007
@@ -305,7 +305,8 @@ const SSOProviderForm = ({ authenticationPortal }: SSOProviderFormProps) => {
id="client-secret"
type="password"
{...field}
value={field.value === null ? '**********************' : field.value}
value={field.value ?? ''}
placeholder={field.value === null ? '**********************' : undefined}
/>
</FormControl>
<FormMessage />