fix(ai): corrected OAuth callback flows and hardened credential storage permissions

- Fixed OAuth callback flows for GitHub Copilot and Google Gemini to handle cancellation and manual input errors.
- Hardened database file permissions to 0o600 and directory creation to 0o700 to prevent credential leakage.
- Fixed cache invalidation for streaming edits and file existence checks for prompt templates.
- Fixed bash output streaming to prevent premature closure and LSP client request handling for aborted signals.
This commit is contained in:
can1357
2026-01-21 01:44:31 +01:00
parent 698751e7fe
commit 87c1de9fab
24 changed files with 146 additions and 435 deletions
@@ -34,7 +34,7 @@ export async function executeBash(command: string, options?: BashExecutorOptions
const prefixedCommand = prefix ? `${prefix} ${command}` : command;
const finalCommand = `${snapshotPrefix}${prefixedCommand}`;
const stream = new OutputSink({ onLine: options?.onChunk });
const stream = new OutputSink({ onChunk: options?.onChunk });
const child = cspawn([shell, ...args, finalCommand], {
cwd: options?.cwd,
@@ -44,6 +44,7 @@ export async function executeBash(command: string, options?: BashExecutorOptions
});
// Pump streams - errors during abort/timeout are expected
// Use preventClose to avoid closing the shared sink when either stream finishes
await Promise.allSettled([
child.stdout.pipeTo(stream.createWritable()),
child.stderr.pipeTo(stream.createWritable()),
@@ -92,7 +93,7 @@ export async function executeBashWithOperations(
operations: BashOperations,
options?: BashExecutorOptions,
): Promise<BashResult> {
const stream = new OutputSink({ onLine: options?.onChunk });
const stream = new OutputSink({ onChunk: options?.onChunk });
const writable = stream.createWritable();
const writer = writable.getWriter();