Files
oh-my-pi/packages/coding-agent/test
oldschoola c6c2c386bc fix: skip all /login args from history (P1 security review)
parseCallbackInput() accepts three forms: redirect URLs, query strings
(?code=...), and raw auth codes — all carry OAuth secrets. The previous
filter only skipped URL-like inputs, leaking query strings and raw codes.

Skip ALL /login commands with any argument. The minor convenience loss
(can't recall /login <provider>) is far less important than the risk of
persisting OAuth authorization codes.
2026-06-23 14:17:35 -07:00
..
2026-06-23 08:18:29 +02:00
2026-06-23 08:18:29 +02:00
2026-06-23 08:18:29 +02:00
2026-06-04 00:56:59 +00:00
2026-06-11 21:03:49 +02:00
2026-05-30 18:08:51 +02:00
2026-05-30 18:08:51 +02:00
2026-06-12 11:24:26 +02:00
2026-06-22 06:19:14 +00:00
2026-05-30 18:08:51 +02:00