Skip to content

fix: don't print secrets on the terminal when load can't change the shell - #28

Merged
iamralch merged 1 commit into
mainfrom
fix/no-secrets-on-terminal
Oct 6, 2026
Merged

iamralch merged 1 commit into
mainfrom
fix/no-secrets-on-terminal

Conversation

@iamralch

@iamralch iamralch commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Without the shell integration, keysafe load printed export GITHUB_TOKEN='…' to stdout. On a terminal, that showed secret values on screen and in the scrollback, and still didn't load anything.

Now, when stdout is a terminal, the integration isn't active and no --format was given, load and unload print nothing on stdout and fail with:

keysafe: error: `load` changes your shell through the shell integration, which isn't active here; add `eval "$(keysafe init zsh)"` to ~/.zshrc, or run `eval "$(keysafe load)"`

Unchanged:

  • eval "$(keysafe load)", scripts and pipes, where stdout isn't a terminal,
  • the shell integration, which reads statements from fd 3,
  • an explicit --format,
  • export, which exists to print statements, and read, which prints the value you asked for.

The check runs before any secret is read, so nothing is fetched or cached when it fails.

Testing: a unit test covers every combination. Manual runs with script, which provides a real terminal: refusal on a terminal, and statements still printed through a pipe.

… shell

Without the shell integration, `load` and `unload` printed their export
statements to stdout. On a terminal that showed secret values on screen,
and in the scrollback, without changing the shell.

When stdout is a terminal, the integration isn't active and no --format
was given, they now print nothing and explain how to set up the
integration or evaluate the output. Evaluated, piped or with an
explicit --format, they print as before.
@iamralch
iamralch merged commit dc8bfd2 into main Oct 6, 2026
8 checks passed
@iamralch
iamralch deleted the fix/no-secrets-on-terminal branch October 6, 2026 06:54
@ralch ralch Bot mentioned this pull request Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant