Skip to content

#941: mask token options regardless of key casing - #958

Open
gemshrine wants to merge 1 commit into
zerocracy:masterfrom
gemshrine:941
Open

gemshrine wants to merge 1 commit into
zerocracy:masterfrom
gemshrine:941

Conversation

@gemshrine

Copy link
Copy Markdown
Contributor

The action accepted token option keys case-insensitively, but the log-masking and token-detection code only matched the lowercase spelling. With verbose logging, an uppercase GITHUB_TOKEN option could bypass masking and also be treated as absent.

The option key is now normalized before masking and token detection. Tracing stays disabled while the option is inspected, and the token value is registered with the Actions log masker before later commands can expand it.

Checks: Bash syntax validation and the entry.sh option-parsing scenario with verbose mode and an uppercase GITHUB_TOKEN key.

Closes #941

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Uppercase token keys are not registered for log masking causing leaks in verbose tracing

1 participant