Skip to content

fix: redact --svc-param values in config show - #83

Open
ConnorMoss02 wants to merge 3 commits into
a2aproject:mainfrom
ConnorMoss02:fix/config-show-redact-svc-param
Open

ConnorMoss02 wants to merge 3 commits into
a2aproject:mainfrom
ConnorMoss02:fix/config-show-redact-svc-param

Conversation

@ConnorMoss02

@ConnorMoss02 ConnorMoss02 commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

config show printed --svc-param values, including Authorization headers, in clear text. Authorization entries now show as Authorization=<redacted>, other headers stay visible, and the unused bearer and api-key names are removed.

Fixes #82

Comment thread internal/clicfg/binder.go Outdated
sensitive := false
switch f.Name {
case "auth", "bearer", "api-key":
case "auth", "bearer", "api-key", "svc-param":

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

how about doing a prefix check for svc-param, not all headers are sensitive. also let's remove bearer and api-key please, we decided to not add these to the cli

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the feedback. Done. Only Authorization values are redacted now, and other headers show as-is. Removed bearer and api-key.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug: config show prints --svc-param credentials in clear text

3 participants