Merge fix/security-audit: CLI credential hardening
This commit is contained in:
@@ -1,6 +1,9 @@
|
||||
package commands
|
||||
|
||||
import (
|
||||
"os"
|
||||
"strings"
|
||||
|
||||
"git.hangman-lab.top/zhi/HarborForge.Cli/internal/mode"
|
||||
"git.hangman-lab.top/zhi/HarborForge.Cli/internal/output"
|
||||
"git.hangman-lab.top/zhi/HarborForge.Cli/internal/passmgr"
|
||||
@@ -20,11 +23,16 @@ func ResolveToken(tokenFlag string) string {
|
||||
}
|
||||
return tok
|
||||
}
|
||||
// manual mode
|
||||
if tokenFlag == "" {
|
||||
output.Error("--token <token> required or execute this with pcexec")
|
||||
// manual mode — prefer the explicit flag, else fall back to the HF_TOKEN
|
||||
// env var so the token need not appear in argv (visible via `ps`/history).
|
||||
if tokenFlag != "" {
|
||||
return tokenFlag
|
||||
}
|
||||
return tokenFlag
|
||||
if env := strings.TrimSpace(os.Getenv("HF_TOKEN")); env != "" {
|
||||
return env
|
||||
}
|
||||
output.Error("--token <token> or HF_TOKEN env required, or execute this with pcexec")
|
||||
return ""
|
||||
}
|
||||
|
||||
// RejectTokenInPaddedCell checks if --token was passed in padded-cell mode
|
||||
|
||||
Reference in New Issue
Block a user