Stacked on !248. Patch fix for #150, reported from use.
repo secret set blocked with nothing printed — indistinguishable from a
hung connection — and pressing Enter did not end it, because the server
reads to EOF. It looked identical before and after the user had done
the right thing, and the token echoed into the scrollback on the way.
Client-side, because whether stdin is a terminal is a fact about the client that the daemon cannot see.
- A terminal is told what is wanted and that Ctrl-D ends it.
- A secret is read without echo and takes a single line, so Enter is enough and the value never reaches the scrollback — which is the point of a rule that already keeps it out of argv and logs.
- Piped input is passed through untouched: no prompt, no byte added or removed. That is the half that can silently corrupt a credential, so it is the half with a test.
- Public keys keep echoing. They are public; hiding them would be
theatre. That distinction is why
stdinSecretis separate fromstdinWhat.
The payload's name rides the command tree as an annotation, so
TestStdinCommandsNameTheirPayload fails when a new stdin command
forgets one and would have prompted with the unhelpful word "input". I
confirmed it is load-bearing by removing a label and watching it name
repo secret set.
Closes #150
retargeted from sonar-scan to main: !248 merged
2026-09-04 19:43 UTC