Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

Support private stdin input for CLI fill without secret-bearing argv

Offen
#3,260 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Maintainer antworten meist innerhalb von 1 Tag

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Anfängerfreundlichkeit
48/100
Issue-Typ
Feature
Klarheit
Größtenteils klar
Aktivitätsstatus
Aktiv
Tech-Stack
typescript
Bereich
cli

Rechercherichtung

Start with the CLI type/fill readers in src/commands/interaction/interactions.ts and read docs/adr/0017-parameterized-recorded-inputs.md to understand the existing sensitivity contract. Work out a supported stdin interface with bounded input and check how it handles results and parse errors. Done means fill can receive input through stdin without exposing its value in argv, results, or parse errors, while remaining compatible with the existing contract.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

We are moving our iOS login automation back to the unmodified official release and would like to supply sensitive input without putting it in the CLI process arguments.

On v0.21.22 (202585240f0c1289642885b5df645cbc25114272), fill receives its text through positional arguments. Expanding a shell variable still puts the value in argv. The existing --record-as NAME protections are useful, but address recording/response/diagnostic handling after input reaches the command.

Could the CLI offer a supported stdin input option for fill, compatible with the existing explicit sensitivity/parameterization contract? For example, an illustrative --text-stdin option could accept bounded input without echoing it in results or parse errors. The exact interface is up to the maintainers.

Current sources:

This is an enhancement request based on the current command interface, not a report of a reproduced credential leak. We recognize that the Node API or replay variables may avoid CLI argv today. A direct CLI path would let secret-store output feed the stock tool without maintaining a separate input adapter.

Related implemented work: #1348 and #1398. This request is specifically about input transport, not a claim that secret redaction is missing.

Vorherrschende Sprache
TypeScript
Sterne
4.9k
Forks
328
Ø Merge
11 Std. 51 Min.
Gemergte PRs (30 T.)
535

Entwicklungsumgebung

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus callstack/agent-device

Alle Issues in callstack/agent-device

Ähnliche Issues

Weitere Issues zu TypeScript

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.