Repository navigation
Fix file permissions on credentials file - #236
Conversation
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Want higher recall? High effort reviews run extra passes and find more bugs. A team admin can switch effort levels in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 9ebfe34. Configure here.
| GLOBAL_ENV_PATH.parent.chmod(0o700) # mkdir leaves an existing directory's mode untouched, so we set it explicitly | ||
| # Create owner-only from the start | ||
| os.close(os.open(GLOBAL_ENV_PATH, os.O_WRONLY | os.O_CREAT, 0o600)) | ||
| GLOBAL_ENV_PATH.chmod(0o600) # tighten a file that already existed |
There was a problem hiding this comment.
Read-only credentials file blocks save
Low Severity
os.open uses O_WRONLY on GLOBAL_ENV_PATH before chmod, so an existing owner-read-only .env raises PermissionError and never gets tightened. save_api_key then cannot rotate the key, including during hai login --force.
Reviewed by Cursor Bugbot for commit 9ebfe34. Configure here.


Issue
save_api_keycreated ~/.config/hai with the default mode (usually 755) and the .env at 644, then ran chmod 600 and ignored any error. The file was briefly readable by other users, and a failed chmod left it that way without warning.Fix
Crete the file with the correct permissions right away
Note
Low Risk
Localized CLI credential persistence change with added tests; no auth protocol or network behavior changes.
Overview
Tightens POSIX permissions when persisting the global API key so the config directory and
.envare owner-only from creation, including when paths already existed with looser modes.save_api_keynow creates the parent directory with mode0o700(andchmods it explicitly), opens the credentials file with0o600, and re-applies0o600on an existing file before writing viaset_key. A POSIX-only test covers both tightening a pre-existing755/644layout and a fresh create path.Also drops a polling helper test that asserted
MAX_REQUEST_BYTES == 5MB, which no longer matches the implementation.Reviewed by Cursor Bugbot for commit 9ebfe34. Bugbot is set up for automated code reviews on this repo. Configure here.