webhook add takes the secret on argv #284

closed cmc opened this on 2026-09-28 05:23 UTC · control security

Discussion

cmc 2026-09-28 05:23 UTC

webhook add takes the signing secret on argv: --secret <s> (internal/control/webhook.go:16-23). Secrets are meant to travel on stdin only, because argv shows up in /proc on the client and in shell history.

  • Read the secret from stdin (--secret -, ReadsStdin: true) and refuse a literal value, the way repo secret set does.
  • Update the web form handler if it builds the argv with the secret, and the API wiki page.

referenced in commit fb6e9dcfa4 by cmc: plans: #287, #284, #298, #285, #297

2026-09-29 00:09 UTC

closed by cmc in commit f8b976a972: webhook: document --secret -, pipe it in the e2e test

2026-09-29 00:19 UTC

referenced in commit ba885de89c by cmc: cli: webhook add forwards stdin for --secret -

2026-09-29 00:19 UTC

referenced in commit 8dcfa45a8a by cmc: webhook: add reads the signing secret from stdin

2026-09-29 00:19 UTC

referenced in commit 132441b6f5 by cmc: control: webhook add trims a CRLF from the secret; --secret - counts as stdin

2026-09-29 02:39 UTC

referenced in commit fad7a633f4 by cmc: changelog: one #297 entry, upgrade notes after the list, #298 note corrected

2026-09-29 02:39 UTC