Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/ISSUE_TEMPLATE/bug_report.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ name: Bug report
about: Something tokenstash did that it should not have, or did not do that it should
---

**Never paste a key value here** — not even a "test" one, not even partially. If the bug is that
**Never paste a key value here**, not even a "test" one, not even partially. If the bug is that
a value showed up somewhere it should not have, that is a security report: use
https://github.com/krishhgg/tokenstash/security/advisories/new instead of an issue.

Expand All @@ -12,6 +12,6 @@ https://github.com/krishhgg/tokenstash/security/advisories/new instead of an iss
- Agent, if one was involved (Claude Code / Codex / Cursor / Gemini CLI / none):

**What you ran**, in order (`tokenstash doctor` output is useful; `tokenstash audit` is fine to
paste — it never contains values):
paste, because it never contains values):

**What happened, and what you expected instead:**
2 changes: 1 addition & 1 deletion .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,4 +2,4 @@ blank_issues_enabled: true
contact_links:
- name: Security report
url: https://github.com/krishhgg/tokenstash/security/advisories/new
about: A value reaching an agent, an approval that should not have happened, anything from SECURITY.md — privately, please.
about: A value reaching an agent, an approval that should not have happened, anything from SECURITY.md. Report it privately, please.
24 changes: 12 additions & 12 deletions CHANGELOG.md

Large diffs are not rendered by default.

18 changes: 9 additions & 9 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,23 +15,23 @@
}
```

- `name` — the exact env var developers use.
- `url` — where a new user creates the key, as deep a link as possible.
- `steps` — what to click, in order. Write them as if for someone who has never used the product.
- `pattern` — regex for the key format, so a bad paste fails immediately. Optional but valuable.
- `check` — one cheap authenticated request that returns 200 with a valid key and 401 without. Optional.
- `name`: the exact env var developers use.
- `url`: where a new user creates the key, as deep a link as possible.
- `steps`: what to click, in order. Write them as if for someone who has never used the product.
- `pattern`: regex for the key format, so a bad paste fails immediately. Optional but valuable.
- `check`: one cheap authenticated request that returns 200 with a valid key and 401 without. Optional.
`auth` is `bearer` | `header:<Name>` | `prefix:<Scheme>` | `basic-user` | `query:<param>`; `method` defaults to GET.
403 is read as "live, lacks permission", never as a dead key; if the provider answers something
other than 401 to a bad key (Google: 400), list it in `reject_status`. Set `at_use: true` only if
the request is free and read-only enough to run before every delivery — without it the check
the request is free and read-only enough to run before every delivery. Without it, the check
runs at paste time only.
- `sensitive: true` — live payment keys, cloud credentials, anything with unbounded spend. These,
- `sensitive: true`: live payment keys, cloud credentials, anything with unbounded spend. These,
and any name the registry does not know, get their own card per directory; the broad pairing
button never covers them. Use `sensitive_pattern` when only some values are dangerous (e.g.
Stripe live vs test).
- `generate: "base64:32"` — for local secrets with no vendor (`AUTH_SECRET`), so no human is involved.
- `generate: "base64:32"`: for local secrets with no vendor (`AUTH_SECRET`), so no human is involved.

Run `cargo test` — `registry_is_sane` validates every entry.
Run `cargo test`. `registry_is_sane` validates every entry.

## Code

Expand Down
121 changes: 66 additions & 55 deletions README.md

Large diffs are not rendered by default.

22 changes: 11 additions & 11 deletions SECURITY.md

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion docs/assets/before-after.svg
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
68 changes: 34 additions & 34 deletions docs/registry-verification.md

Large diffs are not rendered by default.

Loading