referencedSecureKeyNames function
The store-key names the SAVED CONFIG explicitly references (gh-1059):
every custom provider entry's own keyName plus the roles config's
apiKeyNames. Env-only setups reference nothing — the boot warning
must stay silent for them (a missing env key has its own loud banner).
Implementation
Set<String> referencedSecureKeyNames(CliConfig saved) {
return {
for (final entry in saved.customProviders)
if (entry.keyName != null) entry.keyName!,
if (saved.modelRoles != null) ...roleKeyNames(saved.modelRoles!),
};
}