fix(auth): fail fast on non-TTY login and tighten cli.yaml to 0600 - #282
Open
stantheman0128 wants to merge 2 commits into
Open
stantheman0128 wants to merge 2 commits into
stantheman0128 wants to merge 2 commits into
Conversation
Browser OpenURL can return nil on headless Linux (DISPLAY set, Chromium starts, dbus dies) while WaitForToken blocks forever. ModeCharDevice is the wrong test because /dev/null is a char device; use term.IsTerminal. PersistentPreRunE now requires ZEABUR_TOKEN/--token when JSON, -i=false, or stdin is not a terminal, instead of starting the browser callback. GenerateToken always prints the URL and bounds WaitForToken. Also create ~/.config/zeabur/cli.yaml as 0600 (and chmod existing files) so the access token is not world-readable under a default umask. Related to zeabur#280 (survey hang) but a different bug path.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Unauthenticated commands hang forever on headless / non-TTY Linux environments. This is not the survey hang fixed in #280.
Cause
PersistentPreRunEalways callsAuthClient.GenerateTokenwhen not logged in (except--json).browser.OpenURLcan returnnileven when no usable browser exists (e.g.DISPLAY=:1, Chromium starts, dbus/GPU dies).WaitForTokenhas no timeout, so the process blocks forever.-i=falseis ignored inPersistentPreRunE(onlyauth login -i=falsetakes the token path).os.Stdin.Stat()+ModeCharDeviceis the wrong non-TTY test:/dev/nullis a char device, so that check false-positives as a terminal.term.IsTerminalcorrectly returns false for pipes and/dev/null.Separately,
os.Createfor~/.config/zeabur/cli.yamluses0666 & umask→ typically0644while the file holds the access token.Fix
CanCompleteBrowserLogin()viaterm.IsTerminal(stdin).PersistentPreRunE: if not logged in and (JSONor!Interactiveor non-TTY), requireZEABUR_TOKEN/--tokeninstead of opening a browser.GenerateToken: always print the URL; refuse the browser path when stdin is not a terminal; boundWaitForTokento 2 minutes.auth login: only take the browser path when interactive and stdin is a terminal.cli.yamlas0600(directory0700).Relation to #280
#280 adds
ensureTerminalinpkg/promptso survey does not hang. This PR covers the earlier hang: the implicit browser login inPersistentPreRunE/GenerateTokenbefore any prompt runs. Both can occur on the same headless box; they are different code paths.Test plan
go test ./pkg/auth ./pkg/config ./internal/cmd/auth/logintimeout 5 zeabur auth login </dev/null→ exit 1 (was 124)timeout 5 zeabur context clear -i=false </dev/null→ fail-fast, no hangNeed help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.