CLI doesn't have config file like olm
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- go, linux
- Domain
- cli, operating-systems, security
Research direction
Start with the CLI documentation and the systemd unit referenced in the reproduction steps, then trace how the Pangolin client id and secret are supplied to the CLI. Done means Linux users have a documented secret-passing mechanism that does not expose credentials in /proc//environ or ps output.
Written by the indexing model from the issue text.
Description
Describe the Bug
This is a security issue as the client id and secret are always available in /proc/<pid>/environ or in ps output.
Environment
- OS Type & Version: (e.g., Ubuntu 22.04) Any Linux distro
- Pangolin Version: Latest
- Gerbil Version: Latest
- Traefik Version: Latest
- Newt Version: Latest
- Client Version: (if applicable)
To Reproduce
Run pangolin CLI as per the docs provided (including systemd unit) on site, check ps auxf | grep -i pangolin output
Expected Behavior
If this is going to be used for config on Linux machines, there needs to be a mechanism for passing secrets that doesn't expose on CLI or otherwise
- Dominant language
- Go
- Stars
- 50
- Forks
- 18
- Avg merge
- 2d 9h
- Merged PRs (30d)
- 7
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from fosrl/cli
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
Maintainers usually reply within 1 day
-
CLI on Windows not able to switch org (and account)May be free again @oschwartz10612 claimed this 60 days ago, and no pull request is open. Openbug
fosrl/cli#121 · 1 comment · 1 assignee ·
Maintainers usually reply within 1 day
-
Containerized tunnel unusable againMay be free again @oschwartz10612 claimed this 62 days ago, and no pull request is open. Openneeds investigating
fosrl/cli#118 · 14 comments · 1 assignee ·
Maintainers usually reply within 1 day
-
Error messages are sent to stdout, not to stderrMay be free again @marcschaeferger claimed this 131 days ago, and no pull request is open. Openneeds investigating
fosrl/cli#74 · 4 comments · 2 reactions · 1 assignee ·
Maintainers usually reply within 1 day
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 48/100
Maintainers usually reply within 1 day
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
gruntwork-io/boilerplate#329 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
prime-radiant-inc/evener#3291 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Netcracker/qubership-apihub-backend#582 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
Maintainers usually reply within 1 day