Task
Standardize credential handling for the project at $1 (relative path under packages/<domain>/).
Standard Patterns
ESP-IDF Projects
Use credentials.h + credentials.h.example:
// credentials.h.example — Template for project credentials
// Copy to credentials.h and fill in your values:
// cp credentials.h.example credentials.h
#ifndef CREDENTIALS_H
#define CREDENTIALS_H
// WiFi Configuration
#define WIFI_SSID "your-wifi-ssid"
#define WIFI_PASSWORD "your-wifi-password"
// API Keys (uncomment and fill in as needed)
// #define API_KEY "your-api-key"
#endif // CREDENTIALS_H
ESPHome Projects
Use secrets.yaml + secrets.yaml.example:
# secrets.yaml.example — Template for project secrets
# Copy to secrets.yaml and fill in your values:
# cp secrets.yaml.example secrets.yaml
wifi_ssid: "your-wifi-ssid"
wifi_password: "your-wifi-password"
api_encryption_key: "generate-with-esphome"
ota_password: "your-ota-password"
Process
- Detect project type (ESP-IDF or ESPHome) by checking for
CMakeLists.txtvs.yamlconfig - Scan source for credential usage:
#include "credentials.h"or#include "secrets.h"or#include "wifi_config.h"WIFI_SSID,WIFI_PASSWORD,API_KEY, etc.
- Check current state:
- Does a
.examplefile exist? - Is the credential file gitignored?
- Are pre-commit hooks protecting it?
- Does a
- Fix non-conforming patterns:
wifi_config.h/wifi_config_example.h→ rename tocredentials.h/credentials.h.examplesecrets.h/secrets.h.example→ rename tocredentials.h/credentials.h.example- Update
#includestatements in source to match
- Ensure protection:
- Verify
.gitignorecoverscredentials.handsecrets.yaml - Verify root
.pre-commit-config.yamlblocks credential files
- Verify
Migration Table
| Current File | Standard Name | Action |
|---|---|---|
wifi_config.h |
credentials.h |
Rename, update includes |
wifi_config_example.h |
credentials.h.example |
Rename |
secrets.h |
credentials.h |
Rename, update includes |
secrets.h.example |
credentials.h.example |
Rename |
credentials.h.template |
credentials.h.example |
Rename |
credentials.h.example |
(already correct) | No action |
Output
Report what was found and what was changed:
- Current credential pattern detected
- Files renamed/created
- .gitignore status
- Pre-commit protection status
- Source files updated (if includes were changed)