Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

fix(cli): close remaining tty and confirmation gaps in channel and onboard flows

Aperta
#337 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
52/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Tranquilla
Stack tecnologico
python
Ambito
cli, security

Direzione di ricerca

Start with raven/cli/channel_commands.py at the login, set, enable, and _gate_open_allow_from entry points, then inspect raven/channels/adapters/whatsapp/bridge.py:91 and channel.py:53 for the interactive wait behavior. Compare onboard_commands.py:328 with raven/cli/_tty_guard.py:6. Done means login has a bounded or cancellable interactive path, set applies the intended confirmation warning, and onboard rejects non-TTY stdin.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Problem

Recent hardening added non-TTY guards and an allow_from confirmation gate, but three adjacent gaps remain:

  1. Interactive channel login can hang forever. raven channels login whatsapp in a real terminal starts the bridge and blocks until the QR is scanned or the process is killed; there is no timeout, no cancel hint, and no failure path if the user walks away. (Non-TTY invocations are now cleanly rejected with exit 2, but the interactive path is unbounded.)
  2. raven channels set <name> --allow-from '*' silently opens a channel to anyone. The confirmation gate only runs on enable, so set is a quiet bypass of the enable-time gate.
  3. Onboard's TTY check only inspects stdout. raven onboard < /dev/null with a TTY stdout gets past the check and crashes inside questionary when the first prompt reads stdin. The shared guard already checks both directions; onboard should use it.

Evidence

  • WhatsApp login blocks in raven/channels/adapters/whatsapp/bridge.py:91 ("blocks until it exits") behind raven/channels/adapters/whatsapp/channel.py:53; under a forced non-interactive harness the wait had to be killed externally (observed exit 142 via an alarm). The non-TTY guard sits at raven/cli/channel_commands.py:539.
  • _gate_open_allow_from (raven/cli/channel_commands.py:118) is called exactly once, from the enable path at raven/cli/channel_commands.py:288; the set command registered at raven/cli/channel_commands.py:322 never calls it.
  • raven/cli/onboard_commands.py:328 checks sys.stdout.isatty() alone; raven/cli/_tty_guard.py:6 describes itself as "onboard's _check_tty_or_die, plus the stdin check it lacks".

Suggested direction

  • Wrap the interactive login wait with a timeout plus a printed cancel hint (Ctrl-C handling that cleans up the bridge process), or at minimum a periodic "still waiting for QR scan" line.
  • Route set through the same _gate_open_allow_from confirmation used by enable (or at least print the same warning).
  • Switch onboard's _check_tty_or_die to the shared die_if_not_tty guard so stdin is covered.
Lingua principale
Python
Stelle
4.1k
Fork
94
Merge medio
10h 2m
PR unite (30g)
376

Preparare l'ambiente

Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di EverMind-AI/Raven

Tutte le issue di EverMind-AI/Raven

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.