fix: reject inline secrets across runtime and identity credential commands - #2080

Merged
jariy17 merged 2 commits into
refactorfrom
feat/runtime-api-key-resolve-secret
Aug 24, 2026
Merged

fix: reject inline secrets across runtime and identity credential commands#2080
jariy17 merged 2 commits into
refactorfrom
feat/runtime-api-key-resolve-secret

Conversation

@tejaskash

@tejaskashtejaskash commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

What

Route every secret-value flag through SourceResolver.resolveSecret (stdin - or file:// only, single-line enforced, trailing newline stripped) instead of the generic resolveText. Inline secrets on argv leak into shell history, ps output, and CI logs.

Handlers changed:

Also dropped "inline" from those flags' help text so it matches the enforced contract, aligning with the project add credentials handlers.

Not changed: bearer-token invoke paths (ephemeral, never persisted) and structured-config flags (JSON/tags/free text) that legitimately use resolveText.

Testing

  • tsc --noEmit clean.
  • Tests feeding a secret now pipe it via stdin; added inline-rejection coverage for runtime --api-key, and identity api-key + oauth2 create.
  • Full suite: 1742 pass, 0 fail.

…eSecret
The runtime add handler resolved its --api-key with the generic resolveText,
so an inline secret value was accepted and a trailing newline was not stripped.
Switch to resolveSecret (stdin/file only, single-line enforced), matching the
api-key and oauth credential handlers and the flag's documented contract.
@github-actionsgithub-actionsBot added agentcore-harness-reviewing AgentCore Harness review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 24, 2026
The standalone identity api-key/oauth2 credential-provider create and update
handlers resolved their --api-key / --client-secret with the generic
resolveText, so an inline secret value was accepted and a trailing newline was
not stripped. Inline secrets on argv leak into shell history, ps output, and
CI logs. Switch all four to resolveSecret (stdin '-' or file:// only,
single-line enforced) and drop "inline" from the flag help, matching the
project add credentials and runtime handlers.
Tests feeding a secret now pipe it via stdin; added inline-rejection coverage
for api-key and oauth2 create.
@tejaskashtejaskash changed the title fix(project): resolve runtime --api-key through SourceResolver.resolveSecretfix: reject inline secrets across runtime and identity credential commandsAug 24, 2026
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.24%. Comparing base (38c30ae) to head (eaf11b5).

Additional details and impacted files
@@ Coverage Diff @@## refactor #2080 +/- ##
=========================================
Coverage 97.24% 97.24% =========================================
Files 396 396 Lines 24019 24021 +2 =========================================
+ Hits 23357 23359 +2 
Misses 662 662 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@jariy17
jariy17 merged commit b75e1c6 into refactorAug 24, 2026
10 checks passed
@jariy17
jariy17 deleted the feat/runtime-api-key-resolve-secret branch August 24, 2026 16:07
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tejaskash@codecov-commenter@jariy17
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix: reject inline secrets across runtime and identity credential commands - #2080

Merged
jariy17 merged 2 commits into
refactorfrom
feat/runtime-api-key-resolve-secret
Aug 24, 2026
Merged

fix: reject inline secrets across runtime and identity credential commands#2080
jariy17 merged 2 commits into
refactorfrom
feat/runtime-api-key-resolve-secret

Conversation

@tejaskash

@tejaskashtejaskash commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

What

Route every secret-value flag through SourceResolver.resolveSecret (stdin - or file:// only, single-line enforced, trailing newline stripped) instead of the generic resolveText. Inline secrets on argv leak into shell history, ps output, and CI logs.

Handlers changed:

Also dropped "inline" from those flags' help text so it matches the enforced contract, aligning with the project add credentials handlers.

Not changed: bearer-token invoke paths (ephemeral, never persisted) and structured-config flags (JSON/tags/free text) that legitimately use resolveText.

Testing

  • tsc --noEmit clean.
  • Tests feeding a secret now pipe it via stdin; added inline-rejection coverage for runtime --api-key, and identity api-key + oauth2 create.
  • Full suite: 1742 pass, 0 fail.

…eSecret
The runtime add handler resolved its --api-key with the generic resolveText,
so an inline secret value was accepted and a trailing newline was not stripped.
Switch to resolveSecret (stdin/file only, single-line enforced), matching the
api-key and oauth credential handlers and the flag's documented contract.
@github-actionsgithub-actionsBot added agentcore-harness-reviewing AgentCore Harness review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 24, 2026
The standalone identity api-key/oauth2 credential-provider create and update
handlers resolved their --api-key / --client-secret with the generic
resolveText, so an inline secret value was accepted and a trailing newline was
not stripped. Inline secrets on argv leak into shell history, ps output, and
CI logs. Switch all four to resolveSecret (stdin '-' or file:// only,
single-line enforced) and drop "inline" from the flag help, matching the
project add credentials and runtime handlers.
Tests feeding a secret now pipe it via stdin; added inline-rejection coverage
for api-key and oauth2 create.
@tejaskashtejaskash changed the title fix(project): resolve runtime --api-key through SourceResolver.resolveSecretfix: reject inline secrets across runtime and identity credential commandsAug 24, 2026
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.24%. Comparing base (38c30ae) to head (eaf11b5).

Additional details and impacted files
@@ Coverage Diff @@## refactor #2080 +/- ##
=========================================
Coverage 97.24% 97.24% =========================================
Files 396 396 Lines 24019 24021 +2 =========================================
+ Hits 23357 23359 +2 
Misses 662 662 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@jariy17
jariy17 merged commit b75e1c6 into refactorAug 24, 2026
10 checks passed
@jariy17
jariy17 deleted the feat/runtime-api-key-resolve-secret branch August 24, 2026 16:07
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tejaskash@codecov-commenter@jariy17
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: reject inline secrets across runtime and identity credential commands - #2080

Merged
jariy17 merged 2 commits into
refactorfrom
feat/runtime-api-key-resolve-secret
Aug 24, 2026
Merged

fix: reject inline secrets across runtime and identity credential commands#2080
jariy17 merged 2 commits into
refactorfrom
feat/runtime-api-key-resolve-secret

Conversation

@tejaskash

@tejaskashtejaskash commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

What

Route every secret-value flag through SourceResolver.resolveSecret (stdin - or file:// only, single-line enforced, trailing newline stripped) instead of the generic resolveText. Inline secrets on argv leak into shell history, ps output, and CI logs.

Handlers changed:

Also dropped "inline" from those flags' help text so it matches the enforced contract, aligning with the project add credentials handlers.

Not changed: bearer-token invoke paths (ephemeral, never persisted) and structured-config flags (JSON/tags/free text) that legitimately use resolveText.

Testing

  • tsc --noEmit clean.
  • Tests feeding a secret now pipe it via stdin; added inline-rejection coverage for runtime --api-key, and identity api-key + oauth2 create.
  • Full suite: 1742 pass, 0 fail.

…eSecret
The runtime add handler resolved its --api-key with the generic resolveText,
so an inline secret value was accepted and a trailing newline was not stripped.
Switch to resolveSecret (stdin/file only, single-line enforced), matching the
api-key and oauth credential handlers and the flag's documented contract.
@github-actionsgithub-actionsBot added agentcore-harness-reviewing AgentCore Harness review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 24, 2026
The standalone identity api-key/oauth2 credential-provider create and update
handlers resolved their --api-key / --client-secret with the generic
resolveText, so an inline secret value was accepted and a trailing newline was
not stripped. Inline secrets on argv leak into shell history, ps output, and
CI logs. Switch all four to resolveSecret (stdin '-' or file:// only,
single-line enforced) and drop "inline" from the flag help, matching the
project add credentials and runtime handlers.
Tests feeding a secret now pipe it via stdin; added inline-rejection coverage
for api-key and oauth2 create.
@tejaskashtejaskash changed the title fix(project): resolve runtime --api-key through SourceResolver.resolveSecretfix: reject inline secrets across runtime and identity credential commandsAug 24, 2026
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.24%. Comparing base (38c30ae) to head (eaf11b5).

Additional details and impacted files
@@ Coverage Diff @@## refactor #2080 +/- ##
=========================================
Coverage 97.24% 97.24% =========================================
Files 396 396 Lines 24019 24021 +2 =========================================
+ Hits 23357 23359 +2 
Misses 662 662 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@jariy17
jariy17 merged commit b75e1c6 into refactorAug 24, 2026
10 checks passed
@jariy17
jariy17 deleted the feat/runtime-api-key-resolve-secret branch August 24, 2026 16:07
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tejaskash@codecov-commenter@jariy17
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: reject inline secrets across runtime and identity credential commands - #2080

Merged
jariy17 merged 2 commits into
refactorfrom
feat/runtime-api-key-resolve-secret
Aug 24, 2026
Merged

fix: reject inline secrets across runtime and identity credential commands#2080
jariy17 merged 2 commits into
refactorfrom
feat/runtime-api-key-resolve-secret

Conversation

@tejaskash

@tejaskashtejaskash commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

What

Route every secret-value flag through SourceResolver.resolveSecret (stdin - or file:// only, single-line enforced, trailing newline stripped) instead of the generic resolveText. Inline secrets on argv leak into shell history, ps output, and CI logs.

Handlers changed:

Also dropped "inline" from those flags' help text so it matches the enforced contract, aligning with the project add credentials handlers.

Not changed: bearer-token invoke paths (ephemeral, never persisted) and structured-config flags (JSON/tags/free text) that legitimately use resolveText.

Testing

  • tsc --noEmit clean.
  • Tests feeding a secret now pipe it via stdin; added inline-rejection coverage for runtime --api-key, and identity api-key + oauth2 create.
  • Full suite: 1742 pass, 0 fail.

…eSecret
The runtime add handler resolved its --api-key with the generic resolveText,
so an inline secret value was accepted and a trailing newline was not stripped.
Switch to resolveSecret (stdin/file only, single-line enforced), matching the
api-key and oauth credential handlers and the flag's documented contract.
@github-actionsgithub-actionsBot added agentcore-harness-reviewing AgentCore Harness review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 24, 2026
The standalone identity api-key/oauth2 credential-provider create and update
handlers resolved their --api-key / --client-secret with the generic
resolveText, so an inline secret value was accepted and a trailing newline was
not stripped. Inline secrets on argv leak into shell history, ps output, and
CI logs. Switch all four to resolveSecret (stdin '-' or file:// only,
single-line enforced) and drop "inline" from the flag help, matching the
project add credentials and runtime handlers.
Tests feeding a secret now pipe it via stdin; added inline-rejection coverage
for api-key and oauth2 create.
@tejaskashtejaskash changed the title fix(project): resolve runtime --api-key through SourceResolver.resolveSecretfix: reject inline secrets across runtime and identity credential commandsAug 24, 2026
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.24%. Comparing base (38c30ae) to head (eaf11b5).

Additional details and impacted files
@@ Coverage Diff @@## refactor #2080 +/- ##
=========================================
Coverage 97.24% 97.24% =========================================
Files 396 396 Lines 24019 24021 +2 =========================================
+ Hits 23357 23359 +2 
Misses 662 662 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@jariy17
jariy17 merged commit b75e1c6 into refactorAug 24, 2026
10 checks passed
@jariy17
jariy17 deleted the feat/runtime-api-key-resolve-secret branch August 24, 2026 16:07
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tejaskash@codecov-commenter@jariy17
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix: reject inline secrets across runtime and identity credential commands - #2080

Merged
jariy17 merged 2 commits into
refactorfrom
feat/runtime-api-key-resolve-secret
Aug 24, 2026
Merged

fix: reject inline secrets across runtime and identity credential commands#2080
jariy17 merged 2 commits into
refactorfrom
feat/runtime-api-key-resolve-secret

Conversation

@tejaskash

@tejaskashtejaskash commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

What

Route every secret-value flag through SourceResolver.resolveSecret (stdin - or file:// only, single-line enforced, trailing newline stripped) instead of the generic resolveText. Inline secrets on argv leak into shell history, ps output, and CI logs.

Handlers changed:

Also dropped "inline" from those flags' help text so it matches the enforced contract, aligning with the project add credentials handlers.

Not changed: bearer-token invoke paths (ephemeral, never persisted) and structured-config flags (JSON/tags/free text) that legitimately use resolveText.

Testing

  • tsc --noEmit clean.
  • Tests feeding a secret now pipe it via stdin; added inline-rejection coverage for runtime --api-key, and identity api-key + oauth2 create.
  • Full suite: 1742 pass, 0 fail.

…eSecret
The runtime add handler resolved its --api-key with the generic resolveText,
so an inline secret value was accepted and a trailing newline was not stripped.
Switch to resolveSecret (stdin/file only, single-line enforced), matching the
api-key and oauth credential handlers and the flag's documented contract.
@github-actionsgithub-actionsBot added agentcore-harness-reviewing AgentCore Harness review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 24, 2026
The standalone identity api-key/oauth2 credential-provider create and update
handlers resolved their --api-key / --client-secret with the generic
resolveText, so an inline secret value was accepted and a trailing newline was
not stripped. Inline secrets on argv leak into shell history, ps output, and
CI logs. Switch all four to resolveSecret (stdin '-' or file:// only,
single-line enforced) and drop "inline" from the flag help, matching the
project add credentials and runtime handlers.
Tests feeding a secret now pipe it via stdin; added inline-rejection coverage
for api-key and oauth2 create.
@tejaskashtejaskash changed the title fix(project): resolve runtime --api-key through SourceResolver.resolveSecretfix: reject inline secrets across runtime and identity credential commandsAug 24, 2026
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.24%. Comparing base (38c30ae) to head (eaf11b5).

Additional details and impacted files
@@ Coverage Diff @@## refactor #2080 +/- ##
=========================================
Coverage 97.24% 97.24% =========================================
Files 396 396 Lines 24019 24021 +2 =========================================
+ Hits 23357 23359 +2 
Misses 662 662 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@jariy17
jariy17 merged commit b75e1c6 into refactorAug 24, 2026
10 checks passed
@jariy17
jariy17 deleted the feat/runtime-api-key-resolve-secret branch August 24, 2026 16:07
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tejaskash@codecov-commenter@jariy17
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: reject inline secrets across runtime and identity credential commands - #2080

Merged
jariy17 merged 2 commits into
refactorfrom
feat/runtime-api-key-resolve-secret
Aug 24, 2026
Merged

fix: reject inline secrets across runtime and identity credential commands#2080
jariy17 merged 2 commits into
refactorfrom
feat/runtime-api-key-resolve-secret

Conversation

@tejaskash

@tejaskashtejaskash commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

What

Route every secret-value flag through SourceResolver.resolveSecret (stdin - or file:// only, single-line enforced, trailing newline stripped) instead of the generic resolveText. Inline secrets on argv leak into shell history, ps output, and CI logs.

Handlers changed:

Also dropped "inline" from those flags' help text so it matches the enforced contract, aligning with the project add credentials handlers.

Not changed: bearer-token invoke paths (ephemeral, never persisted) and structured-config flags (JSON/tags/free text) that legitimately use resolveText.

Testing

  • tsc --noEmit clean.
  • Tests feeding a secret now pipe it via stdin; added inline-rejection coverage for runtime --api-key, and identity api-key + oauth2 create.
  • Full suite: 1742 pass, 0 fail.

…eSecret
The runtime add handler resolved its --api-key with the generic resolveText,
so an inline secret value was accepted and a trailing newline was not stripped.
Switch to resolveSecret (stdin/file only, single-line enforced), matching the
api-key and oauth credential handlers and the flag's documented contract.
@github-actionsgithub-actionsBot added agentcore-harness-reviewing AgentCore Harness review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 24, 2026
The standalone identity api-key/oauth2 credential-provider create and update
handlers resolved their --api-key / --client-secret with the generic
resolveText, so an inline secret value was accepted and a trailing newline was
not stripped. Inline secrets on argv leak into shell history, ps output, and
CI logs. Switch all four to resolveSecret (stdin '-' or file:// only,
single-line enforced) and drop "inline" from the flag help, matching the
project add credentials and runtime handlers.
Tests feeding a secret now pipe it via stdin; added inline-rejection coverage
for api-key and oauth2 create.
@tejaskashtejaskash changed the title fix(project): resolve runtime --api-key through SourceResolver.resolveSecretfix: reject inline secrets across runtime and identity credential commandsAug 24, 2026
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.24%. Comparing base (38c30ae) to head (eaf11b5).

Additional details and impacted files
@@ Coverage Diff @@## refactor #2080 +/- ##
=========================================
Coverage 97.24% 97.24% =========================================
Files 396 396 Lines 24019 24021 +2 =========================================
+ Hits 23357 23359 +2 
Misses 662 662 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@jariy17
jariy17 merged commit b75e1c6 into refactorAug 24, 2026
10 checks passed
@jariy17
jariy17 deleted the feat/runtime-api-key-resolve-secret branch August 24, 2026 16:07
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tejaskash@codecov-commenter@jariy17
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: reject inline secrets across runtime and identity credential commands - #2080

Merged
jariy17 merged 2 commits into
refactorfrom
feat/runtime-api-key-resolve-secret
Aug 24, 2026
Merged

fix: reject inline secrets across runtime and identity credential commands#2080
jariy17 merged 2 commits into
refactorfrom
feat/runtime-api-key-resolve-secret

Conversation

@tejaskash

@tejaskashtejaskash commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

What

Route every secret-value flag through SourceResolver.resolveSecret (stdin - or file:// only, single-line enforced, trailing newline stripped) instead of the generic resolveText. Inline secrets on argv leak into shell history, ps output, and CI logs.

Handlers changed:

Also dropped "inline" from those flags' help text so it matches the enforced contract, aligning with the project add credentials handlers.

Not changed: bearer-token invoke paths (ephemeral, never persisted) and structured-config flags (JSON/tags/free text) that legitimately use resolveText.

Testing

  • tsc --noEmit clean.
  • Tests feeding a secret now pipe it via stdin; added inline-rejection coverage for runtime --api-key, and identity api-key + oauth2 create.
  • Full suite: 1742 pass, 0 fail.

…eSecret
The runtime add handler resolved its --api-key with the generic resolveText,
so an inline secret value was accepted and a trailing newline was not stripped.
Switch to resolveSecret (stdin/file only, single-line enforced), matching the
api-key and oauth credential handlers and the flag's documented contract.
@github-actionsgithub-actionsBot added agentcore-harness-reviewing AgentCore Harness review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 24, 2026
The standalone identity api-key/oauth2 credential-provider create and update
handlers resolved their --api-key / --client-secret with the generic
resolveText, so an inline secret value was accepted and a trailing newline was
not stripped. Inline secrets on argv leak into shell history, ps output, and
CI logs. Switch all four to resolveSecret (stdin '-' or file:// only,
single-line enforced) and drop "inline" from the flag help, matching the
project add credentials and runtime handlers.
Tests feeding a secret now pipe it via stdin; added inline-rejection coverage
for api-key and oauth2 create.
@tejaskashtejaskash changed the title fix(project): resolve runtime --api-key through SourceResolver.resolveSecretfix: reject inline secrets across runtime and identity credential commandsAug 24, 2026
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.24%. Comparing base (38c30ae) to head (eaf11b5).

Additional details and impacted files
@@ Coverage Diff @@## refactor #2080 +/- ##
=========================================
Coverage 97.24% 97.24% =========================================
Files 396 396 Lines 24019 24021 +2 =========================================
+ Hits 23357 23359 +2 
Misses 662 662 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@jariy17
jariy17 merged commit b75e1c6 into refactorAug 24, 2026
10 checks passed
@jariy17
jariy17 deleted the feat/runtime-api-key-resolve-secret branch August 24, 2026 16:07
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tejaskash@codecov-commenter@jariy17
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix: reject inline secrets across runtime and identity credential commands - #2080

Merged
jariy17 merged 2 commits into
refactorfrom
feat/runtime-api-key-resolve-secret
Aug 24, 2026
Merged

fix: reject inline secrets across runtime and identity credential commands#2080
jariy17 merged 2 commits into
refactorfrom
feat/runtime-api-key-resolve-secret

Conversation

@tejaskash

@tejaskashtejaskash commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

What

Route every secret-value flag through SourceResolver.resolveSecret (stdin - or file:// only, single-line enforced, trailing newline stripped) instead of the generic resolveText. Inline secrets on argv leak into shell history, ps output, and CI logs.

Handlers changed:

Also dropped "inline" from those flags' help text so it matches the enforced contract, aligning with the project add credentials handlers.

Not changed: bearer-token invoke paths (ephemeral, never persisted) and structured-config flags (JSON/tags/free text) that legitimately use resolveText.

Testing

  • tsc --noEmit clean.
  • Tests feeding a secret now pipe it via stdin; added inline-rejection coverage for runtime --api-key, and identity api-key + oauth2 create.
  • Full suite: 1742 pass, 0 fail.

…eSecret
The runtime add handler resolved its --api-key with the generic resolveText,
so an inline secret value was accepted and a trailing newline was not stripped.
Switch to resolveSecret (stdin/file only, single-line enforced), matching the
api-key and oauth credential handlers and the flag's documented contract.
@github-actionsgithub-actionsBot added agentcore-harness-reviewing AgentCore Harness review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 24, 2026
The standalone identity api-key/oauth2 credential-provider create and update
handlers resolved their --api-key / --client-secret with the generic
resolveText, so an inline secret value was accepted and a trailing newline was
not stripped. Inline secrets on argv leak into shell history, ps output, and
CI logs. Switch all four to resolveSecret (stdin '-' or file:// only,
single-line enforced) and drop "inline" from the flag help, matching the
project add credentials and runtime handlers.
Tests feeding a secret now pipe it via stdin; added inline-rejection coverage
for api-key and oauth2 create.
@tejaskashtejaskash changed the title fix(project): resolve runtime --api-key through SourceResolver.resolveSecretfix: reject inline secrets across runtime and identity credential commandsAug 24, 2026
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.24%. Comparing base (38c30ae) to head (eaf11b5).

Additional details and impacted files
@@ Coverage Diff @@## refactor #2080 +/- ##
=========================================
Coverage 97.24% 97.24% =========================================
Files 396 396 Lines 24019 24021 +2 =========================================
+ Hits 23357 23359 +2 
Misses 662 662 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@jariy17
jariy17 merged commit b75e1c6 into refactorAug 24, 2026
10 checks passed
@jariy17
jariy17 deleted the feat/runtime-api-key-resolve-secret branch August 24, 2026 16:07
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tejaskash@codecov-commenter@jariy17