Hacktoberfest 2026: as issues que os mantenedores marcaram para outubro, abertas e boas para iniciantes. Ver issues do Hacktoberfest

bug(auth): preserve rc tokens before process.env can truncate embedded NULs

Aberta
#1,646 0 comentários 0 reações 0 responsáveis Ver no GitHub

Mantenedores costumam responder em até 1 dia

Ninguém assumiu esta issue ainda.

Avaliação

Dificuldade
4/5
Tempo estimado
3-5 dias
Facilidade para iniciantes
52/100
Tipo de issue
Bug
Clareza
Razoavelmente clara
Status de atividade
Ativa
Stack de tecnologia
node.js, typescript
Domínio
authentication, cli

Direção de pesquisa

Trace token parsing and environment handling through packages/cli/src/lib/ini.ts, packages/cli/src/lib/sentryclirc.ts, packages/cli/src/lib/env.ts, and packages/cli/src/cli.ts, starting with applySentryCliRcEnvShim and the auth selector. Use the suggested regression cases to verify NUL handling, precedence, recovery commands, and CLI/SDK parity; done means the complete credential reaches validation without breaking those behaviors.

Escrita pelo modelo de indexação a partir do texto da issue.

Descrição

An access token containing an embedded NUL in .sentryclirc can be silently truncated before bearer validation sees it.

Confirmed locally against e0fdee49a347255bbbb072dfc74baf53ae5998de, using synthetic data and no network requests:

  1. Parse INI content containing token = synthetic-prefix\u0000synthetic-tail with an actual NUL byte in the value.
  2. parseIni preserves the complete string.
  3. In CLI mode, getEnv() returns process.env.
  4. applySentryCliRcEnvShim assigns the token to env.SENTRY_AUTH_TOKEN; Node truncates the value at the NUL.
  5. The auth selector and bearer validator receive only synthetic-prefix, which is printable and passes format validation.

Expected: preserve the complete credential until it is validated, so an internal NUL is rejected without transmitting a truncated prefix. Surrounding padding may follow the shared token-normalization policy.

Do not simply throw from the boot-time shim: that runs before command routing and would also block help/login/logout, or reject an rc token that stored OAuth should ignore. Avoid switching identities by silently dropping the invalid token. A fix should preserve existing environment precedence and recovery commands, and account for context.env and subprocess inheritance if environment storage changes.

Suggested regressions: an embedded NUL in a selected rc token, an invalid rc token shadowed by stored OAuth, explicit env precedence, recovery commands, and parity between CLI/process.env and SDK/in-memory environments.

Relevant files: packages/cli/src/lib/ini.ts, packages/cli/src/lib/sentryclirc.ts, packages/cli/src/lib/env.ts, and packages/cli/src/cli.ts.

Linguagem predominante
TypeScript
Estrelas
123
Forks
14
Merge médio
23h 39min
PRs com merge (30d)
81

Preparar o ambiente

Este projeto não oferece contêiner de desenvolvimento, Dockerfile nem guia de contribuição, então a configuração fica por sua conta: comece pelo README e veja nosso guia da primeira contribuição para os passos gerais.

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Mais de getsentry/cli

Todas as issues de getsentry/cli

Issues semelhantes

Mais issues de TypeScript

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.