Support private stdin input for CLI fill without secret-bearing argv
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 48/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- typescript
- Lĩnh vực
- cli
Hướng nghiên cứu
Start with the CLI type/fill readers in src/commands/interaction/interactions.ts and read docs/adr/0017-parameterized-recorded-inputs.md to understand the existing sensitivity contract. Work out a supported stdin interface with bounded input and check how it handles results and parse errors. Done means fill can receive input through stdin without exposing its value in argv, results, or parse errors, while remaining compatible with the existing contract.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
We are moving our iOS login automation back to the unmodified official release and would like to supply sensitive input without putting it in the CLI process arguments.
On v0.21.22 (202585240f0c1289642885b5df645cbc25114272), fill receives its text through positional arguments. Expanding a shell variable still puts the value in argv. The existing --record-as NAME protections are useful, but address recording/response/diagnostic handling after input reaches the command.
Could the CLI offer a supported stdin input option for fill, compatible with the existing explicit sensitivity/parameterization contract? For example, an illustrative --text-stdin option could accept bounded input without echoing it in results or parse errors. The exact interface is up to the maintainers.
Current sources:
This is an enhancement request based on the current command interface, not a report of a reproduced credential leak. We recognize that the Node API or replay variables may avoid CLI argv today. A direct CLI path would let secret-store output feed the stock tool without maintaining a separate input adapter.
Related implemented work: #1348 and #1398. This request is specifically about input transport, not a claim that secret redaction is missing.
- Ngôn ngữ chính
- TypeScript
- Star
- 4.9k
- Fork
- 328
- Merge trung bình
- 12 giờ 13 phút
- Pull request đã merge (30 ngày)
- 541
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của callstack/agent-device
-
settings clear-app-state fails with ENOENT … scandir '(null)' for iOS system apps such as SettingsCó thể đã có người làm @thymikee đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 80/100
callstack/agent-device#3305 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
callstack/agent-device#1869 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
install and reinstall from another session in the same daemon replace the app on a claimed deviceĐang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 55/100
callstack/agent-device#3345 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
callstack/agent-device#3344 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100
callstack/agent-device#3342 · 7 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của callstack/agent-device
Issue tương tự
-
Độ khó 1/5 1-3 giờ Mức phù hợp với người mới 84/100
Maintainer thường phản hồi trong vòng 1 ngày
-
core
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
vectorize-io/hindsight#5457 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
beginner friendly community contributions-welcome good first issue hacktoberfest help wanted testing up-for-grabs
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 85/100
lukilabs/beautiful-mermaid#160 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 66/100
rescript-lang/rescript-lang.org#1420 ·
Maintainer thường phản hồi trong vòng 2 ngày