mirror of https://github.com/garrytan/gstack.git
saveApiKey wrote ~/.gstack/openai.json at the default umask (typically
0644) and only tightened it to 0600 with a following chmodSync. Between
the write and the chmod the file containing the OpenAI API key is
group/world-readable, so any local user on a shared host can read the key
in that window (CWE-377 insecure file creation / CWE-367 TOCTOU).
Pass { mode: 0o600 } to writeFileSync so the file is created owner-only up
front, matching the convention already used for session files in
design/src/session.ts (#859). The trailing chmodSync is kept as a backstop
to tighten a pre-existing loose file.
Adds a regression test asserting the key file is 0600 (no group/other
bits) even when written under a permissive umask.
|
||
|---|---|---|
| .. | ||
| src | ||
| test | ||
| prototype.ts | ||