From 6e94e390078fa8a923d2a5b27a193bdf342d3289 Mon Sep 17 00:00:00 2001 From: Catalin Pit Date: Thu, 1 Oct 2026 15:36:04 +0100 Subject: [PATCH] fix: use placeholder for stored sso client secret instead of a masked value The client secret input rendered a string of asterisks as the input's value whenever a secret was already stored. Because the input is controlled, clicking into the field and pasting a new secret without selecting all appended it to the asterisks, and the submit path stored the concatenated string, breaking SSO login for the organisation. Render the field empty and show the dots as a placeholder instead, so pasting replaces cleanly. The placeholder only appears while the form value is null (stored secret untouched), so a fresh portal or a cleared field renders empty rather than suggesting a secret is still being kept. Fixes #3183 --- .../app/routes/_authenticated+/o.$orgUrl.settings.sso.tsx | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/apps/remix/app/routes/_authenticated+/o.$orgUrl.settings.sso.tsx b/apps/remix/app/routes/_authenticated+/o.$orgUrl.settings.sso.tsx index 1536c1a1b..b72943380 100644 --- a/apps/remix/app/routes/_authenticated+/o.$orgUrl.settings.sso.tsx +++ b/apps/remix/app/routes/_authenticated+/o.$orgUrl.settings.sso.tsx @@ -305,7 +305,8 @@ const SSOProviderForm = ({ authenticationPortal }: SSOProviderFormProps) => { id="client-secret" type="password" {...field} - value={field.value === null ? '**********************' : field.value} + value={field.value ?? ''} + placeholder={field.value === null ? '**********************' : undefined} />