Avoid exposing Git credentials in subprocess command-line arguments
还没有人认领这个 Issue。
评估
调研方向
定位构建 Git 子进程参数并处理包含凭据的配置的代码,然后追踪其对授权值和仓库 URL 的验证。检查子进程环境是如何组装的,包括现有的 GIT_CONFIG_* 条目和格式错误的计数。完成标准是凭据不出现在子进程参数中,同时配置保留、验证和作用域授权行为仍由测试覆盖。
由索引模型根据 Issue 内容生成。
描述
Description
Cachew currently passes repository-scoped authorization credentials to Git using command-line configuration:
git -c credential.helper=<helper containing credential> ...
The credential is embedded as a literal in the helper definition, which exposes it in Git's process arguments. Command-line arguments may be visible through process inspection tools, /proc/<pid>/cmdline, diagnostic tooling, or process telemetry.
PR #321 also identified that credentials are embedded in the helper command, but addressed token refresh during long-running subprocesses. It was closed in favor of #322, which addressed token lifetime and LFS timeouts without removing credentials from process arguments.
Proposed change
Pass credential-bearing Git configuration through Git's environment-based configuration mechanism instead:
GIT_CONFIG_COUNT=<n>
GIT_CONFIG_KEY_<n>=http.<repository-scope>.extraHeader
GIT_CONFIG_VALUE_<n>=Authorization: <credential>
The implementation should:
- Preserve existing
GIT_CONFIG_COUNT,GIT_CONFIG_KEY_*, andGIT_CONFIG_VALUE_*entries. - Append the credential configuration at the next available index.
- Reject malformed, negative, or overflowing
GIT_CONFIG_COUNTvalues. - Continue validating the authorization value and repository URL scope.
- Restrict this change to credential-bearing configuration; ordinary non-sensitive Git configuration can remain in command-line arguments.
- Ensure credentials do not appear in the generated Git subprocess arguments.
Security impact
This reduces accidental credential disclosure through process listings and command-line capture. The credential remains in the child process environment, as required by Git, so access to process environments should still be restricted appropriately.
- 主要语言
- Go
- 星标
- 41
- 派生
- 14
- 平均合并
- 19 小时 28 分钟
- 30 天内合并 PR
- 3
环境准备
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
block/cachew 的其他 Issue
-
etag-range-followup
难度 2/5 1-3 小时 新手友好度 75/100
-
难度 5/5 一周以上 新手友好度 30/100
-
难度 5/5 一周以上 新手友好度 38/100
-
难度 5/5 一周以上 新手友好度 25/100
-
难度 5/5 一周以上 新手友好度 25/100
相似的 Issue
-
agentic-workflows
难度 2/5 1-3 小时 新手友好度 68/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 82/100
维护者通常 1 天内回复
-
priority/4/normal status/needs-triage type/bug/unconfirmed
难度 2/5 1-3 小时 新手友好度 78/100
authelia/authelia#13292 · 1 条评论 ·
维护者通常 1 天内回复
-
bug
难度 2/5 1-3 小时 新手友好度 68/100
blinklabs-io/actions#138 ·
维护者通常 1 天内回复
-
[UI] AlbumDetails collapses multi-genre list to single primary genre on viewports < lg breakpoint未关闭
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复