From 254afd67faee51368c1c49df841e38119fe7a7cc Mon Sep 17 00:00:00 2001 From: Tommy Rantti Date: Sat, 26 Sep 2026 20:11:27 +0300 Subject: [PATCH] Add masked token diagnostics for 401 debugging Print length + first/last 4 chars of the captured token instead of the full secret, and strip stray whitespace (a trailing newline in a copied token can silently truncate what read captures mid-paste). Helps distinguish a truncated paste from an actually-wrong token without exposing the credential in scrollback. Co-Authored-By: Claude Sonnet 5 --- bootstrap.sh | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/bootstrap.sh b/bootstrap.sh index a89df29..6cb402b 100755 --- a/bootstrap.sh +++ b/bootstrap.sh @@ -281,6 +281,12 @@ forgejo_ssh_key() { local token read -rsp "Forgejo access token (used once, not stored): " token echo + token="${token//[[:space:]]/}" + if [ -z "$token" ]; then + echo "Captured: empty (nothing came through - paste may not have worked in this terminal)" + else + echo "Captured: length=${#token} chars, ${token:0:4}...${token: -4}" + fi local tmpbody status tmpbody=$(mktemp)