login: restore u.Redacted() in parseLoginServer errors · Entire

login: restore u.Redacted() in parseLoginServer errors

7fc8614→main·

toothbrush·1mo ago·1 file·+8 added/-5 removed

The rebase onto the updated part-1 branch resolved login.go to the demolition side wholesale, dropping the base's redaction of rejected --server values — a userinfo-bearing URL must not land in CI logs.

Co-Authored-By: Claude Fable 5 noreply@anthropic.com

Sessions

0dd9fc48dac4View transcript

[?
Auth Refactor: Eliminate Static FallbacksClaude Code·Fable 5.[1m]·2 steps](/content/gh/entireio/cli/session/e6146684-ebfa-4f57-beff-34194cac8c2a#timeline-0dd9fc48dac4/index.html)

Changes

1

123 unmodified lines

124
125
126
127
128
129
130
131
129
132
133
131
134
135
133
136
137
135
138
139
137
140
141
142
143

123 unmodified lines

if err != nil {
        return "", fmt.Errorf("parse server URL: %w", err)
    }
    // Error messages echo u.Redacted(), not raw: the URL may carry
    // userinfo (that's one of the rejection cases), and stderr often ends
    // up in CI logs where a password must not appear.
    switch {
    case u.Scheme != schemeHTTPS && u.Scheme != schemeHTTP:
        return "", fmt.Errorf("scheme must be http or https, got %q", raw)
        return "", fmt.Errorf("scheme must be http or https, got %q", u.Redacted())
    case u.Host == "":
        return "", fmt.Errorf("missing host in %q", raw)
        return "", fmt.Errorf("missing host in %q", u.Redacted())
    case u.User != nil:
        return "", fmt.Errorf("userinfo not allowed in %q", raw)
        return "", fmt.Errorf("userinfo not allowed in %q", u.Redacted())
    case u.Path != "" && u.Path != "/":
        return "", fmt.Errorf("path not allowed in %q (use the bare origin)", raw)
        return "", fmt.Errorf("path not allowed in %q (use the bare origin)", u.Redacted())
    case u.RawQuery != "" || u.Fragment != "":
        return "", fmt.Errorf("query/fragment not allowed in %q", raw)
        return "", fmt.Errorf("query/fragment not allowed in %q", u.Redacted())
    }
    return api.NormalizeOriginURL(raw), nil
}

Mcmd/entire/cli/login.go+8/-5