Capture Forgejo token with cat instead of read -e

readline's bracketed-paste handling didn't reliably prevent the
paste-leaking-into-shell issue in practice (likely tmux/terminal
paste passthrough not cooperating). Reading raw stdin until EOF
(Ctrl-D) sidesteps the problem entirely - it doesn't depend on any
terminal capability, it just keeps consuming bytes including embedded
newlines until you explicitly signal you're done. Token is visible
while pasting now (no -s); acceptable since this only matters on a
personal machine where terminal history exposure isn't a concern.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Tommy Rantti 2026-09-26 20:18:35 +03:00
parent 07c02bb512
commit 48ad7c24e4

View file

@ -278,9 +278,9 @@ forgejo_ssh_key() {
echo "Applications tab -> Manage Access Tokens -> name it, grant 'write:user'"
echo "scope (or tick 'user' read+write) -> Generate Token -> copy it now, it's"
echo "only shown once."
echo "Paste the token below, then press Enter and then Ctrl-D to finish:"
local token
read -r -s -e -p "Forgejo access token (used once, not stored): " token
echo
token=$(cat)
token="${token//[[:space:]]/}"
if [ -z "$token" ]; then
echo "Captured: empty (nothing came through - paste may not have worked in this terminal)"