An access token containing an embedded NUL in .sentryclirc can be silently truncated before bearer validation sees it.
Confirmed locally against e0fdee49a347255bbbb072dfc74baf53ae5998de, using synthetic data and no network requests:
- Parse INI content containing
token = synthetic-prefix\u0000synthetic-tail with an actual NUL byte in the value.
parseIni preserves the complete string.
- In CLI mode,
getEnv() returns process.env.
applySentryCliRcEnvShim assigns the token to env.SENTRY_AUTH_TOKEN; Node truncates the value at the NUL.
- The auth selector and bearer validator receive only
synthetic-prefix, which is printable and passes format validation.
Expected: preserve the complete credential until it is validated, so an internal NUL is rejected without transmitting a truncated prefix. Surrounding padding may follow the shared token-normalization policy.
Do not simply throw from the boot-time shim: that runs before command routing and would also block help/login/logout, or reject an rc token that stored OAuth should ignore. Avoid switching identities by silently dropping the invalid token. A fix should preserve existing environment precedence and recovery commands, and account for context.env and subprocess inheritance if environment storage changes.
Suggested regressions: an embedded NUL in a selected rc token, an invalid rc token shadowed by stored OAuth, explicit env precedence, recovery commands, and parity between CLI/process.env and SDK/in-memory environments.
Relevant files: packages/cli/src/lib/ini.ts, packages/cli/src/lib/sentryclirc.ts, packages/cli/src/lib/env.ts, and packages/cli/src/cli.ts.
An access token containing an embedded NUL in
.sentryclirccan be silently truncated before bearer validation sees it.Confirmed locally against
e0fdee49a347255bbbb072dfc74baf53ae5998de, using synthetic data and no network requests:token = synthetic-prefix\u0000synthetic-tailwith an actual NUL byte in the value.parseInipreserves the complete string.getEnv()returnsprocess.env.applySentryCliRcEnvShimassigns the token toenv.SENTRY_AUTH_TOKEN; Node truncates the value at the NUL.synthetic-prefix, which is printable and passes format validation.Expected: preserve the complete credential until it is validated, so an internal NUL is rejected without transmitting a truncated prefix. Surrounding padding may follow the shared token-normalization policy.
Do not simply throw from the boot-time shim: that runs before command routing and would also block help/login/logout, or reject an rc token that stored OAuth should ignore. Avoid switching identities by silently dropping the invalid token. A fix should preserve existing environment precedence and recovery commands, and account for
context.envand subprocess inheritance if environment storage changes.Suggested regressions: an embedded NUL in a selected rc token, an invalid rc token shadowed by stored OAuth, explicit env precedence, recovery commands, and parity between CLI/process.env and SDK/in-memory environments.
Relevant files:
packages/cli/src/lib/ini.ts,packages/cli/src/lib/sentryclirc.ts,packages/cli/src/lib/env.ts, andpackages/cli/src/cli.ts.