-
Notifications
You must be signed in to change notification settings - Fork 15.4k
security: OPENCODE_SERVER_PASSWORD is kept in process env post consumption #14567
Copy link
Copy link
Open
Labels
bugSomething isn't workingSomething isn't workingcoreAnything pertaining to core functionality of the application (opencode server stuff)Anything pertaining to core functionality of the application (opencode server stuff)
Description
Description
OPENCODE_SERVER_PASSWORD continues to be stick around in the process's env. When running headless in docker, the only way to set OPENCODE_SERVER_PASSWORD is to put it in the env at start, but this should be removed once consumed, as a security measure to avoid potential future leakage into spawned processes.
Plugins
No response
OpenCode version
v1.2.10
Steps to reproduce
No response
Screenshot and/or share link
No response
Operating System
Docker
Terminal
No response
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't workingcoreAnything pertaining to core functionality of the application (opencode server stuff)Anything pertaining to core functionality of the application (opencode server stuff)
Type
Fields
Give feedbackNo fields configured for issues without a type.