Skip to content

Fix file permissions on credentials file - #236

Merged
abonneth merged 2 commits into
mainfrom
ivan/save-api-fix
Oct 5, 2026
Merged

abonneth merged 2 commits into
mainfrom
ivan/save-api-fix

Conversation

@ivanvalentini-h

@ivanvalentini-h ivanvalentini-h commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Issue

save_api_key created ~/.config/hai with the default mode (usually 755) and the .env at 644, then ran chmod 600 and ignored any error. The file was briefly readable by other users, and a failed chmod left it that way without warning.

Fix

Crete the file with the correct permissions right away


Note

Low Risk
Localized CLI credential persistence change with added tests; no auth protocol or network behavior changes.

Overview
Tightens POSIX permissions when persisting the global API key so the config directory and .env are owner-only from creation, including when paths already existed with looser modes.

save_api_key now creates the parent directory with mode 0o700 (and chmods it explicitly), opens the credentials file with 0o600, and re-applies 0o600 on an existing file before writing via set_key. A POSIX-only test covers both tightening a pre-existing 755/644 layout and a fresh create path.

Also drops a polling helper test that asserted MAX_REQUEST_BYTES == 5MB, which no longer matches the implementation.

Reviewed by Cursor Bugbot for commit 9ebfe34. Bugbot is set up for automated code reviews on this repo. Configure here.

@ivanvalentini-h ivanvalentini-h changed the title Ivan/save api fix Fix file permissions on credentials file Oct 5, 2026
@abonneth
abonneth merged commit 2f68205 into main Oct 5, 2026
6 checks passed
@abonneth
abonneth deleted the ivan/save-api-fix branch October 5, 2026 14:55

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want higher recall? High effort reviews run extra passes and find more bugs. A team admin can switch effort levels in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 9ebfe34. Configure here.

GLOBAL_ENV_PATH.parent.chmod(0o700) # mkdir leaves an existing directory's mode untouched, so we set it explicitly
# Create owner-only from the start
os.close(os.open(GLOBAL_ENV_PATH, os.O_WRONLY | os.O_CREAT, 0o600))
GLOBAL_ENV_PATH.chmod(0o600) # tighten a file that already existed

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Read-only credentials file blocks save

Low Severity

os.open uses O_WRONLY on GLOBAL_ENV_PATH before chmod, so an existing owner-read-only .env raises PermissionError and never gets tightened. save_api_key then cannot rotate the key, including during hai login --force.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 9ebfe34. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants