Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

bug(auth): preserve rc tokens before process.env can truncate embedded NULs

Abierto
#1,646 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
52/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
node.js, typescript

Línea de trabajo

Trace token parsing and environment handling through packages/cli/src/lib/ini.ts, packages/cli/src/lib/sentryclirc.ts, packages/cli/src/lib/env.ts, and packages/cli/src/cli.ts, starting with applySentryCliRcEnvShim and the auth selector. Use the suggested regression cases to verify NUL handling, precedence, recovery commands, and CLI/SDK parity; done means the complete credential reaches validation without breaking those behaviors.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

An access token containing an embedded NUL in .sentryclirc can be silently truncated before bearer validation sees it.

Confirmed locally against e0fdee49a347255bbbb072dfc74baf53ae5998de, using synthetic data and no network requests:

  1. Parse INI content containing token = synthetic-prefix\u0000synthetic-tail with an actual NUL byte in the value.
  2. parseIni preserves the complete string.
  3. In CLI mode, getEnv() returns process.env.
  4. applySentryCliRcEnvShim assigns the token to env.SENTRY_AUTH_TOKEN; Node truncates the value at the NUL.
  5. The auth selector and bearer validator receive only synthetic-prefix, which is printable and passes format validation.

Expected: preserve the complete credential until it is validated, so an internal NUL is rejected without transmitting a truncated prefix. Surrounding padding may follow the shared token-normalization policy.

Do not simply throw from the boot-time shim: that runs before command routing and would also block help/login/logout, or reject an rc token that stored OAuth should ignore. Avoid switching identities by silently dropping the invalid token. A fix should preserve existing environment precedence and recovery commands, and account for context.env and subprocess inheritance if environment storage changes.

Suggested regressions: an embedded NUL in a selected rc token, an invalid rc token shadowed by stored OAuth, explicit env precedence, recovery commands, and parity between CLI/process.env and SDK/in-memory environments.

Relevant files: packages/cli/src/lib/ini.ts, packages/cli/src/lib/sentryclirc.ts, packages/cli/src/lib/env.ts, and packages/cli/src/cli.ts.

Lenguaje dominante
TypeScript
Estrellas
123
Forks
14
Merge medio
1 d 2 h
PR fusionados (30 d)
70

Preparar el entorno

Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de getsentry/cli

Todos los issues de getsentry/cli

Issues similares

Más issues de TypeScript

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.