Skip to content

bug(auth): preserve rc tokens before process.env can truncate embedded NULs #1646

Description

@betegon

An access token containing an embedded NUL in .sentryclirc can be silently truncated before bearer validation sees it.

Confirmed locally against e0fdee49a347255bbbb072dfc74baf53ae5998de, using synthetic data and no network requests:

  1. Parse INI content containing token = synthetic-prefix\u0000synthetic-tail with an actual NUL byte in the value.
  2. parseIni preserves the complete string.
  3. In CLI mode, getEnv() returns process.env.
  4. applySentryCliRcEnvShim assigns the token to env.SENTRY_AUTH_TOKEN; Node truncates the value at the NUL.
  5. The auth selector and bearer validator receive only synthetic-prefix, which is printable and passes format validation.

Expected: preserve the complete credential until it is validated, so an internal NUL is rejected without transmitting a truncated prefix. Surrounding padding may follow the shared token-normalization policy.

Do not simply throw from the boot-time shim: that runs before command routing and would also block help/login/logout, or reject an rc token that stored OAuth should ignore. Avoid switching identities by silently dropping the invalid token. A fix should preserve existing environment precedence and recovery commands, and account for context.env and subprocess inheritance if environment storage changes.

Suggested regressions: an embedded NUL in a selected rc token, an invalid rc token shadowed by stored OAuth, explicit env precedence, recovery commands, and parity between CLI/process.env and SDK/in-memory environments.

Relevant files: packages/cli/src/lib/ini.ts, packages/cli/src/lib/sentryclirc.ts, packages/cli/src/lib/env.ts, and packages/cli/src/cli.ts.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions