login: restore u.Redacted() in parseLoginServer errors · Entire
login: restore u.Redacted() in parseLoginServer errors
7fc8614→main·
toothbrush·1mo ago·1 file·+8 added/-5 removed
The rebase onto the updated part-1 branch resolved login.go to the demolition side wholesale, dropping the base's redaction of rejected --server values — a userinfo-bearing URL must not land in CI logs.
Co-Authored-By: Claude Fable 5 noreply@anthropic.com
Sessions
0dd9fc48dac4View transcript
[?
Auth Refactor: Eliminate Static FallbacksClaude Code·Fable 5.[1m]·2 steps](/content/gh/entireio/cli/session/e6146684-ebfa-4f57-beff-34194cac8c2a#timeline-0dd9fc48dac4/index.html)
Changes
1
cmd/entire/cli
Mlogin.go+8/-5
123 unmodified lines
124
125
126
127
128
129
130
131
129
132
133
131
134
135
133
136
137
135
138
139
137
140
141
142
143
123 unmodified lines
if err != nil {
return "", fmt.Errorf("parse server URL: %w", err)
}
// Error messages echo u.Redacted(), not raw: the URL may carry
// userinfo (that's one of the rejection cases), and stderr often ends
// up in CI logs where a password must not appear.
switch {
case u.Scheme != schemeHTTPS && u.Scheme != schemeHTTP:
return "", fmt.Errorf("scheme must be http or https, got %q", raw)
return "", fmt.Errorf("scheme must be http or https, got %q", u.Redacted())
case u.Host == "":
return "", fmt.Errorf("missing host in %q", raw)
return "", fmt.Errorf("missing host in %q", u.Redacted())
case u.User != nil:
return "", fmt.Errorf("userinfo not allowed in %q", raw)
return "", fmt.Errorf("userinfo not allowed in %q", u.Redacted())
case u.Path != "" && u.Path != "/":
return "", fmt.Errorf("path not allowed in %q (use the bare origin)", raw)
return "", fmt.Errorf("path not allowed in %q (use the bare origin)", u.Redacted())
case u.RawQuery != "" || u.Fragment != "":
return "", fmt.Errorf("query/fragment not allowed in %q", raw)
return "", fmt.Errorf("query/fragment not allowed in %q", u.Redacted())
}
return api.NormalizeOriginURL(raw), nil
}
Mcmd/entire/cli/login.go+8/-5