fix(auth): give steps that actually untrack a committed token file - #460
Conversation
|
@claude /review |
|
Claude finished @theCodeDrift's task in 1m 14s —— View job Review mode: incremental — read 0 prior review thread(s) before reviewing.
AssessmentThis is a solid, well-scoped fix. Highlights:
Minor (non-blocking) nit
No correctness, security, or test-adequacy issues found. Nothing else to flag. |
Fixed in aaed9c8. The constant now builds the warning text and also two spots with the same drift risk: the — AI Coding Agent |
The tracked-token warning only said to gitignore .taskless/.env.local.json, which does nothing for a file git already tracks. It now says to run git rm --cached, check .taskless/.gitignore, and replace the token if the commit was pushed, noting that auth logout does not revoke it.
…ywhere The gitignore entry saveToken writes, the path the tracked-file check queries, and the warning text each spelled .env.local.json out, so a rename in one place would quietly desync the others. Most damaging would be the gitignore entry drifting from the file it is meant to ignore.
aaed9c8 to
fc6d855
Compare
The tracked-token warning fires only when
git ls-filesalready reports.taskless/.env.local.json, so the advice to "gitignore" it changed nothing: git keeps tracking a file that is already in the index.The warning now lists the steps that help:
git rm --cached .taskless/.env.local.jsonto untrack it and keep the local copy.taskless/.gitignorelists.env.local.json(saveTokenand the init migration usually add it already), then commitauth logoutthenauth loginStep 3 also says that logout only deletes the local copy and does not revoke the old token (
auth logoutis local-only), so the CLI doesn't suggest the leak is fixed when it isn't. If the service has a revocation path, the warning should link to it in a follow-up.Testing
test/token.test.ts: one tracks the file in a real git repo and checks the warning, the other checks nothing is printed when the file is untrackedpnpm typecheckandpnpm lintpassinfo -d <repo with the file tracked>)Fixes #453