From 48ad7c24e44b313f207c9aef9f98cca0f4d5a0bf Mon Sep 17 00:00:00 2001 From: Tommy Rantti Date: Sat, 26 Sep 2026 20:18:35 +0300 Subject: [PATCH] Capture Forgejo token with cat instead of read -e readline's bracketed-paste handling didn't reliably prevent the paste-leaking-into-shell issue in practice (likely tmux/terminal paste passthrough not cooperating). Reading raw stdin until EOF (Ctrl-D) sidesteps the problem entirely - it doesn't depend on any terminal capability, it just keeps consuming bytes including embedded newlines until you explicitly signal you're done. Token is visible while pasting now (no -s); acceptable since this only matters on a personal machine where terminal history exposure isn't a concern. Co-Authored-By: Claude Sonnet 5 --- bootstrap.sh | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/bootstrap.sh b/bootstrap.sh index e3726ec..78c7439 100755 --- a/bootstrap.sh +++ b/bootstrap.sh @@ -278,9 +278,9 @@ forgejo_ssh_key() { echo "Applications tab -> Manage Access Tokens -> name it, grant 'write:user'" echo "scope (or tick 'user' read+write) -> Generate Token -> copy it now, it's" echo "only shown once." + echo "Paste the token below, then press Enter and then Ctrl-D to finish:" local token - read -r -s -e -p "Forgejo access token (used once, not stored): " token - echo + token=$(cat) token="${token//[[:space:]]/}" if [ -z "$token" ]; then echo "Captured: empty (nothing came through - paste may not have worked in this terminal)"