Commit graph

6 commits

Author SHA1 Message Date
48ad7c24e4 Capture Forgejo token with cat instead of read -e
readline's bracketed-paste handling didn't reliably prevent the
paste-leaking-into-shell issue in practice (likely tmux/terminal
paste passthrough not cooperating). Reading raw stdin until EOF
(Ctrl-D) sidesteps the problem entirely - it doesn't depend on any
terminal capability, it just keeps consuming bytes including embedded
newlines until you explicitly signal you're done. Token is visible
while pasting now (no -s); acceptable since this only matters on a
personal machine where terminal history exposure isn't a concern.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-26 20:18:35 +03:00
07c02bb512 Use readline for the token prompt to prevent paste leaking into shell
Plain `read -rsp` has no paste awareness: a token with a trailing
newline (common from some "copy token" UI buttons) terminates the
read early, and whatever came after in the paste is left in the
terminal's input buffer - which the shell then executes as a command
once the script exits. `read -e` uses GNU readline, which honors
bracketed paste and inserts a multi-line paste as literal text
instead of treating embedded newlines as Enter.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-26 20:15:14 +03:00
254afd67fa Add masked token diagnostics for 401 debugging
Print length + first/last 4 chars of the captured token instead of
the full secret, and strip stray whitespace (a trailing newline in a
copied token can silently truncate what read captures mid-paste).
Helps distinguish a truncated paste from an actually-wrong token
without exposing the credential in scrollback.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-26 20:11:27 +03:00
079c3e4f10 Remember Forgejo URL and key label across runs
Persist the last-entered values to ~/.config/travel-bootstrap/config
and offer them as the prompt default, so a re-run only needs Enter
instead of retyping the same values every time.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-26 20:08:28 +03:00
d52d1060ce Improve Forgejo API error reporting and add token instructions
curl -f collapsed auth failures, wrong paths, and real network errors
into the same vague "could not reach" message. Now reports the actual
HTTP status and response body, and prompts print exactly where to
generate a Forgejo access token before asking for it.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-26 20:05:37 +03:00
1bddb438ea Add travel laptop bootstrap script
Idempotent setup for a disposable Debian travel laptop: base packages
(vim, tmux, mosh, tailscale, uv, VS Code + Remote-SSH, firefox-esr),
tailscale join, SSH config regenerated from live tailnet peers (wildcard
+ per-peer entries), fresh SSH key registered to Forgejo via API, and
Firefox hardened to forced-incognito with no history and forced uBlock
Origin. No repos cloned by default - workflow starts as pure Remote-SSH
to the home machine, local clones added opportunistically per project.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-26 19:29:15 +03:00