Skip to content

sec(cli): the --yes flag skips the purchase confirmation on irreversible RI buys #1943

Description

@cristim

Summary

The CLI registers a --yes boolean flag that sets SkipConfirmation, and ConfirmPurchase returns true immediately when it is set, ahead of both the TTY check and the prompt. A single discoverable flag removes the only remaining human gate on a non-reversible, multi-thousand-dollar reserved-instance purchase. The project's standing rule is that the confirmation runs on every invocation. There is a TestDryRunFlagRemoved guard against reintroducing --dry-run, but nothing equivalent guards --yes.

Location

  • cmd/main.go:124 at 3c0f8ac
  • cmd/helpers.go:207-215 (the early return in ConfirmPurchase)

Failure scenario

An operator runs cudly --purchase --yes. ConfirmPurchase(..., skipConfirmation=true) returns true without printing the "About to purchase N instances" line and without reading stdin. The purchase proceeds unattended. The flag reaches exactly two call sites, the main purchase path at cmd/multi_service.go:158 and the CSV per-region prompt at cmd/multi_service.go:701. Dry runs are unaffected, since both sites sit behind a !isDryRun guard and dry runs never prompt.

Evidence

rootCmd.Flags().BoolVar(&toolCfg.SkipConfirmation, "yes", false, "Skip confirmation prompt for purchases (use with caution)")

Suggested fix

Remove the flag and the SkipConfirmation field, drop the parameter from ConfirmPurchase, and add a regression test asserting rootCmd.Flags().Lookup("yes") == nil alongside the existing TestDryRunFlagRemoved in cmd/effective_dry_run_test.go.


Found by the 2026-09-02 codebase audit, finding A10-005, reported by one reviewer and independently confirmed by a second. Full report: docs/audits/codebase-audit-2026-09-02.md.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions