From 52fbcdbf39c484d8b321cba0ee84df1c5d529a75 Mon Sep 17 00:00:00 2001 From: Leo Date: Mon, 4 May 2026 13:19:53 -0700 Subject: [PATCH] fix(credentials): raise when sentinel placeholder hits an invalid element MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit When a known credential sentinel (e.g. PASSWORD = "mycoolpassword") was supplied for a fill action but the targeted element failed the field's validate_element check, replace_credentials silently logged at trace and returned the action unmodified — causing the literal placeholder string to be typed into the form. This was easy to hit by targeting a