gstack/design
Bunlong Heng ab4da32cb9 fix(design): create OpenAI key file owner-only to close write-then-chmod race
saveApiKey wrote ~/.gstack/openai.json at the default umask (typically
0644) and only tightened it to 0600 with a following chmodSync. Between
the write and the chmod the file containing the OpenAI API key is
group/world-readable, so any local user on a shared host can read the key
in that window (CWE-377 insecure file creation / CWE-367 TOCTOU).

Pass { mode: 0o600 } to writeFileSync so the file is created owner-only up
front, matching the convention already used for session files in
design/src/session.ts (#859). The trailing chmodSync is kept as a backstop
to tighten a pre-existing loose file.

Adds a regression test asserting the key file is 0600 (no group/other
bits) even when written under a permissive umask.
2026-08-06 13:59:54 -04:00
..
src fix(design): create OpenAI key file owner-only to close write-then-chmod race 2026-08-06 13:59:54 -04:00
test fix(design): create OpenAI key file owner-only to close write-then-chmod race 2026-08-06 13:59:54 -04:00
prototype.ts v1.30.0.0 fix wave: 21 community PRs + Windows CI extension + codex flag-semantics smoke (#1391) 2026-05-09 08:06:47 -07:00