secrets set --env-file prints secret values in its parse error
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 68/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- typescript
Hướng nghiên cứu
Start at the implementation of supabase secrets set --env-file and trace how malformed env-file lines are parsed and turned into errors. Reproduce both examples with fake values, then verify that failures report the filename and line number without including line content; add or run the relevant parser and CLI tests if present.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Describe the bug
When supabase secrets set --env-file <file> cannot parse a line of the file, the
error message includes the file's content. The file exists only to hold secrets, so
this prints secret values to the terminal, and from there into CI logs, shell
scrollback and AI-assistant transcripts.
We hit this in production. The file held a bare token (no KEY= prefix) by
mistake. The command failed, as it should, but the error printed the live token
and we had to revoke and rotate it. The same thing happens with a value whose
closing quote is missing (KEY="value).
To reproduce (fake values only)
printf 'eyJhbGciOiJIUzI1NiJ9.FAKE-NOT-A-REAL-TOKEN.signature\n' > /tmp/bad.env
supabase secrets set --env-file /tmp/bad.env --project-ref <any-project>
printf 'MY_KEY="fake-value-without-closing-quote\n' > /tmp/bad2.env
supabase secrets set --env-file /tmp/bad2.env --project-ref <any-project>
In both cases the error output contains the fake value.
Expected behavior
The error names the file and the line number (for example
/tmp/bad.env:1: expected KEY=VALUE) and never prints the line's content. A parser
for a secrets file should treat every byte of it as secret, including in error
messages.
System information
- Supabase CLI version: 2.78.1
- OS: Linux (Ubuntu, x86_64)
Additional context
Our workaround is to set Edge Function secrets through the Management API
(POST /v1/projects/{ref}/secrets) with a JSON body built in memory, and to block
secrets set --env-file in our automation. The same "don't echo the input on a
parse error" rule probably applies to any other CLI command that reads an env file.
- Ngôn ngữ chính
- TypeScript
- Star
- 2.4k
- Fork
- 526
- Merge trung bình
- 1 ngày 38 phút
- Pull request đã merge (30 ngày)
- 271
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của supabase/cli
-
🐛 Bug supabase/cli
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
Maintainer thường phản hồi trong vòng 1 ngày
-
🐛 Bug supabase/cli
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 67/100
supabase/cli#6846 · 1 bình luận · 1 người được giao ·
Maintainer thường phản hồi trong vòng 1 ngày
-
✨ Feature supabase/cli
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 45/100
Maintainer thường phản hồi trong vòng 1 ngày
-
bug supabase/cli
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 65/100
Maintainer thường phản hồi trong vòng 1 ngày
-
test new accepts parent-directory names and creates files outside supabase/testsCó thể đã có người làm @7ttp đã nhận 4 ngày trước. Đang mở🐛 Bug supabase/cli
supabase/cli#6742 · 1 người được giao ·
Maintainer thường phản hồi trong vòng 1 ngày
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
rohitg00/agentmemory#1428 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
boxlite-ai/boxlite#1729 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Detect Deno tasks from deno.jsonĐang mởdetectors enhancement good first issue
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
SM260845/readme-gen#1 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
angular/angularfire#3774 ·
Maintainer thường phản hồi trong vòng 2 ngày