Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

`token` commands echo a mistyped secret key given in the `--to` param back in the "alias not found" error

已关闭 适合新手
#2,771 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
2/5
预计耗时
1-3 小时
新手友好度
72/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
活跃
技术栈
rust
领域
cli, security

调研方向

使用一个具有 secret 形式的无效值,重现报告中的 token transfer、token allowance 和 token balance 案例,同时检查文本输出和 JSON 输出。跟踪 --to、--spender 和 --account 参数的共享处理逻辑;完成的标准是具有 secret 形式的无效输入不会被回显,同时普通的别名错误仍然易于理解。

由索引模型根据 Issue 内容生成。

描述

bug
What version are you using?

stellar-cli 28.1.0 (d0b26d9, built from main).

What did you do?

I accidentally passed something shaped like a secret key, but invalid, where an address was expected. Here a made-up S… string stands in for a mistyped secret:

stellar token transfer --id native --from alice --amount 1 --network testnet \
  --to SBADKEYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
What did you expect to see?

An error that doesn't repeat the value back, like the one --from gives for the same input.

What did you see instead?

--from hides the value:

❌ error: invalid signing key or identity name

but --to prints it in full, in both text and JSON output:

❌ error: Account alias "SBADKEYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA" not Found

{"error":{"type":"invalid_address","message":"Account alias \"SBADKEYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\" not Found"}}

With a real secret that has a one-character typo, this prints a near-copy of the secret to the terminal, logs and JSON consumers. token allowance --spender and token balance --account print it the same way.

主要语言
Rust
星标
123
派生
147
平均合并
1 天 4 小时
30 天内合并 PR
31

环境准备

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

stellar/stellar-cli 的其他 Issue

查看 stellar/stellar-cli 的全部 Issue

相似的 Issue

更多 Rust Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。