Hacktoberfest 2026 : les issues que les mainteneurs ont marquées pour octobre, ouvertes et accessibles aux débutants. Parcourir les issues Hacktoberfest

Support private stdin input for CLI fill without secret-bearing argv

Ouverte
#3,260 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub

Les mainteneurs répondent en général sous 1 jour

Personne n'a encore pris cette issue.

Évaluation

Difficulté
4/5
Temps estimé
3-5 jours
Accessibilité débutants
48/100
Type d'issue
Fonctionnalité
Clarté
Plutôt claire
Activité
Active
Stack technique
typescript
Domaine
cli

Piste de recherche

Start with the CLI type/fill readers in src/commands/interaction/interactions.ts and read docs/adr/0017-parameterized-recorded-inputs.md to understand the existing sensitivity contract. Work out a supported stdin interface with bounded input and check how it handles results and parse errors. Done means fill can receive input through stdin without exposing its value in argv, results, or parse errors, while remaining compatible with the existing contract.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Description

We are moving our iOS login automation back to the unmodified official release and would like to supply sensitive input without putting it in the CLI process arguments.

On v0.21.22 (202585240f0c1289642885b5df645cbc25114272), fill receives its text through positional arguments. Expanding a shell variable still puts the value in argv. The existing --record-as NAME protections are useful, but address recording/response/diagnostic handling after input reaches the command.

Could the CLI offer a supported stdin input option for fill, compatible with the existing explicit sensitivity/parameterization contract? For example, an illustrative --text-stdin option could accept bounded input without echoing it in results or parse errors. The exact interface is up to the maintainers.

Current sources:

This is an enhancement request based on the current command interface, not a report of a reproduced credential leak. We recognize that the Node API or replay variables may avoid CLI argv today. A direct CLI path would let secret-store output feed the stock tool without maintaining a separate input adapter.

Related implemented work: #1348 and #1398. This request is specifically about input transport, not a claim that secret redaction is missing.

Langage dominant
TypeScript
Étoiles
4.9k
Forks
328
Merge moyen
11 h 51 min
PR mergées (30 j)
535

Préparer son environnement

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Autres issues de callstack/agent-device

Toutes les issues de callstack/agent-device

Issues similaires

Plus d'issues TypeScript

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.