Add masked token diagnostics for 401 debugging

Print length + first/last 4 chars of the captured token instead of
the full secret, and strip stray whitespace (a trailing newline in a
copied token can silently truncate what read captures mid-paste).
Helps distinguish a truncated paste from an actually-wrong token
without exposing the credential in scrollback.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Tommy Rantti 2026-09-26 20:11:27 +03:00
parent 079c3e4f10
commit 254afd67fa

View file

@ -281,6 +281,12 @@ forgejo_ssh_key() {
local token local token
read -rsp "Forgejo access token (used once, not stored): " token read -rsp "Forgejo access token (used once, not stored): " token
echo echo
token="${token//[[:space:]]/}"
if [ -z "$token" ]; then
echo "Captured: empty (nothing came through - paste may not have worked in this terminal)"
else
echo "Captured: length=${#token} chars, ${token:0:4}...${token: -4}"
fi
local tmpbody status local tmpbody status
tmpbody=$(mktemp) tmpbody=$(mktemp)