fix(plugins): run gh auth token under the noninteractive git env

The MCP-catalog noninteractive contract test asserts every subprocess spawned during a git
install carries GIT_TERMINAL_PROMPT=0 and a closed stdin; the gh token probe was spawned with
the inherited env. Use the same hardened env (plus GH_PROMPT_DISABLED) so gh cannot open a
browser/device flow either, and let the contract accept a stdin fed by input= (credential fill
writes its request and closes).
This commit is contained in:
Teknium
2026-09-09 16:58:26 -07:00
parent 9886f6e53b
commit d783c312a7
2 changed files with 6 additions and 3 deletions
+4 -2
View File
@@ -27,7 +27,7 @@ import subprocess
import urllib.parse
from typing import Mapping, Optional
from hermes_cli._subprocess_compat import windows_hide_flags
from hermes_cli._subprocess_compat import noninteractive_git_env, windows_hide_flags
logger = logging.getLogger(__name__)
@@ -54,9 +54,11 @@ def _github_token() -> Optional[str]:
if not gh:
return None
try:
env = noninteractive_git_env()
env["GH_PROMPT_DISABLED"] = "1"
result = subprocess.run(
[gh, "auth", "token"], capture_output=True, text=True, encoding="utf-8", errors="replace",
timeout=10, stdin=subprocess.DEVNULL, creationflags=windows_hide_flags())
timeout=10, stdin=subprocess.DEVNULL, env=env, creationflags=windows_hide_flags())
except (OSError, subprocess.TimeoutExpired) as exc:
logger.debug("gh auth token lookup failed: %s", exc)
return None