Skip to content

fix(secret-guard): expand variables and close glob bypasses - #1196

Open
TheGreatAxios wants to merge 11 commits into
mainfrom
cl-8999-secret-guard-dollar
Open

TheGreatAxios wants to merge 11 commits into
mainfrom
cl-8999-secret-guard-dollar

Conversation

@TheGreatAxios

@TheGreatAxios TheGreatAxios commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Expands supported shell-variable forms before secret-path matching.
  • Prompts on secret-shaped ?, […], dotfile-rooted *, and local file: URL brace globs while keeping remote URL brace syntax exempt.
  • Decodes local file URL pathnames exactly once and inspects the pathname before fragments.
  • Leaves curl @file handling for separate follow-up work.

Verification

  • bun test src/plugins/secret-guard-plugin.test.ts src/permission/auto-shell-policy.test.ts: 216 pass, 0 fail.
  • Six adjacent secret-guard, classification, and auto-shell suites: 377 pass, 0 fail.
  • bun test src/shell src/permission --randomize --seed 424242: 941 pass, 0 fail.
  • bun run build passes.
  • bun run check passes formatting and lint, then stops at the pre-existing missing semver declaration in vendor/intx-types.

Fixes CL-8999

Tokens like $HOME/.env or ${CFG}/settings.json skipped every shell filter through a blanket includes("$") exemption, so secret-guard never prompted for them. Expand $VAR, ${VAR}, ${VAR:-default}, and ~ against process.env only (never shells out) at the top of isSensitiveShellToken; unexpandable references fail closed to a prompt while single-quoted command substitution stays literal. cmd keeps $ literal so ADS paths such as .flaskenv::$DATA still match.
@linear-code

linear-code Bot commented Sep 28, 2026

Copy link
Copy Markdown

CL-8999

@TheGreatAxios TheGreatAxios changed the title CL-8999: secret-guard expands shell variables before secret matching fix(secret-guard): expand variables and close glob bypasses Sep 28, 2026
@TheGreatAxios
TheGreatAxios force-pushed the cl-8999-secret-guard-dollar branch from 1a01620 to 7980a30 Compare September 28, 2026 20:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant