Repository navigation
fix: don't print secrets on the terminal when load can't change the shell - #28
Merged
Merged
Conversation
… shell Without the shell integration, `load` and `unload` printed their export statements to stdout. On a terminal that showed secret values on screen, and in the scrollback, without changing the shell. When stdout is a terminal, the integration isn't active and no --format was given, they now print nothing and explain how to set up the integration or evaluate the output. Evaluated, piped or with an explicit --format, they print as before.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Without the shell integration,
keysafe loadprintedexport GITHUB_TOKEN='…'to stdout. On a terminal, that showed secret values on screen and in the scrollback, and still didn't load anything.Now, when stdout is a terminal, the integration isn't active and no
--formatwas given,loadandunloadprint nothing on stdout and fail with:Unchanged:
eval "$(keysafe load)", scripts and pipes, where stdout isn't a terminal,--format,export, which exists to print statements, andread, which prints the value you asked for.The check runs before any secret is read, so nothing is fetched or cached when it fails.
Testing: a unit test covers every combination. Manual runs with
script, which provides a real terminal: refusal on a terminal, and statements still printed through a pipe.