fix(plugins): run gh auth token under the noninteractive git env
The MCP-catalog noninteractive contract test asserts every subprocess spawned during a git install carries GIT_TERMINAL_PROMPT=0 and a closed stdin; the gh token probe was spawned with the inherited env. Use the same hardened env (plus GH_PROMPT_DISABLED) so gh cannot open a browser/device flow either, and let the contract accept a stdin fed by input= (credential fill writes its request and closes).
This commit is contained in:
@@ -27,7 +27,7 @@ import subprocess
|
||||
import urllib.parse
|
||||
from typing import Mapping, Optional
|
||||
|
||||
from hermes_cli._subprocess_compat import windows_hide_flags
|
||||
from hermes_cli._subprocess_compat import noninteractive_git_env, windows_hide_flags
|
||||
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
@@ -54,9 +54,11 @@ def _github_token() -> Optional[str]:
|
||||
if not gh:
|
||||
return None
|
||||
try:
|
||||
env = noninteractive_git_env()
|
||||
env["GH_PROMPT_DISABLED"] = "1"
|
||||
result = subprocess.run(
|
||||
[gh, "auth", "token"], capture_output=True, text=True, encoding="utf-8", errors="replace",
|
||||
timeout=10, stdin=subprocess.DEVNULL, creationflags=windows_hide_flags())
|
||||
timeout=10, stdin=subprocess.DEVNULL, env=env, creationflags=windows_hide_flags())
|
||||
except (OSError, subprocess.TimeoutExpired) as exc:
|
||||
logger.debug("gh auth token lookup failed: %s", exc)
|
||||
return None
|
||||
|
||||
@@ -202,7 +202,8 @@ def _capture_run(monkeypatch, module, **result_kwargs):
|
||||
|
||||
|
||||
def _assert_noninteractive(call: dict):
|
||||
assert call.get("stdin") is subprocess.DEVNULL, call["argv"]
|
||||
# A stdin fed by ``input=`` (git credential fill's request) is written and closed, not a terminal.
|
||||
assert call.get("stdin") is subprocess.DEVNULL or "input" in call, call["argv"]
|
||||
env = call.get("env")
|
||||
assert env is not None and env.get("GIT_TERMINAL_PROMPT") == "0", call["argv"]
|
||||
|
||||
|
||||
Reference in New Issue
Block a user