From 07c02bb51293b323059001d879f8b41e3f57dbad Mon Sep 17 00:00:00 2001 From: Tommy Rantti Date: Sat, 26 Sep 2026 20:15:14 +0300 Subject: [PATCH] Use readline for the token prompt to prevent paste leaking into shell Plain `read -rsp` has no paste awareness: a token with a trailing newline (common from some "copy token" UI buttons) terminates the read early, and whatever came after in the paste is left in the terminal's input buffer - which the shell then executes as a command once the script exits. `read -e` uses GNU readline, which honors bracketed paste and inserts a multi-line paste as literal text instead of treating embedded newlines as Enter. Co-Authored-By: Claude Sonnet 5 --- bootstrap.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/bootstrap.sh b/bootstrap.sh index 6cb402b..e3726ec 100755 --- a/bootstrap.sh +++ b/bootstrap.sh @@ -279,7 +279,7 @@ forgejo_ssh_key() { echo "scope (or tick 'user' read+write) -> Generate Token -> copy it now, it's" echo "only shown once." local token - read -rsp "Forgejo access token (used once, not stored): " token + read -r -s -e -p "Forgejo access token (used once, not stored): " token echo token="${token//[[:space:]]/}" if [ -z "$token" ]; then