mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-03 14:09:42 +02:00
fix(repo-status): async git, single-flight TTL cache, credential redaction, local-upstream parse
Post-merge follow-ups for #328 (GET /api/system/repo-status): - Event-loop blocking: every git invocation in repo-status.ts is now async (promisified execFile), never execFileSync — the per-remote ls-remote + fetch could hold the event loop (SSE, PTY streaming) for up to ~60s per request. The whole computation is single-flight with a 45s TTL cache (createSingleFlightCache): concurrent requests share one in-flight promise, a fresh result is served without spawning git, and a rejected compute is never cached. Route handler shape and response fields unchanged; remotes still processed sequentially (concurrent fetches in one repo contend on ref locks). - Credential disclosure: the redaction from git-clone.ts is extracted as exported redactGitCredentials() (sanitizeGitOutput now uses it) and applied via redactRemoteStatus() to every remote card's url and error string, so a scheme://user:token@host remote URL (or git stderr echoing it) never reaches a client. - Non-interactive env: runGit() now uses the shared gitNonInteractiveEnv() instead of a partial GIT_TERMINAL_PROMPT/BatchMode env, also closing the GIT_ASKPASS/SSH_ASKPASS/SSH_ASKPASS_REQUIRE/DISPLAY/GCM_INTERACTIVE prompt paths. - Upstream parse bug: a local-branch upstream (@{upstream} with no slash, e.g. after `git branch -u otherbranch`) made slice(0, indexOf('/')) into slice(0, -1) and yielded garbage like "maste". parseTrackingRemote() (pure, unit-tested) returns null for it, and the bare ref is dropped so it cannot be mistaken for a remote-tracking ref downstream. Tests extended in test/repo-status.test.ts (parseTrackingRemote, redactGitCredentials/redactRemoteStatus, createSingleFlightCache single-flight/TTL/rejection semantics). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
+11
-2
@@ -479,14 +479,23 @@ export function gitNonInteractiveEnv(base: NodeJS.ProcessEnv = process.env): Nod
|
||||
|
||||
// ─── Pure: output handling ───────────────────────────────────────────────────
|
||||
|
||||
/**
|
||||
* Redact any `scheme://user:secret@host` credential pair embedded in text — a
|
||||
* remote URL stored with an inline token, or git stderr echoing such a URL
|
||||
* back. Shared by the clone error path (`sanitizeGitOutput`) and the
|
||||
* repository-status card fields (`web/repo-status.ts`).
|
||||
*/
|
||||
export function redactGitCredentials(text: string): string {
|
||||
return text.replace(/([a-zA-Z][a-zA-Z0-9+.-]*:\/\/)[^/@\s]*:[^/@\s]*@/g, '$1***:***@');
|
||||
}
|
||||
|
||||
/**
|
||||
* Make git's stderr safe to show in the browser: strip ANSI/control bytes,
|
||||
* redact any `scheme://user:secret@host` that a credential helper echoed back,
|
||||
* and keep only the tail (the last lines are the ones that say why it failed).
|
||||
*/
|
||||
export function sanitizeGitOutput(text: string, maxBytes = MAX_STDERR_BYTES): string {
|
||||
const redacted = text
|
||||
.replace(/([a-zA-Z][a-zA-Z0-9+.-]*:\/\/)[^/@\s]*:[^/@\s]*@/g, '$1***:***@')
|
||||
const redacted = redactGitCredentials(text)
|
||||
// eslint-disable-next-line no-control-regex -- deliberate: strip C0/C1 and DEL.
|
||||
.replace(/[\u0000-\u0008\u000b\u000c\u000e-\u001f\u007f-\u009f]/g, '')
|
||||
.trim();
|
||||
|
||||
Reference in New Issue
Block a user