Skip to content

fix: restrict .openclaude-profile.json to owner-only permissions (0600) - #33

Merged
kevincodex1 merged 1 commit into
Twigpine:mainfrom
auriti:fix/profile-file-permissions
Apr 2, 2026
Merged

kevincodex1 merged 1 commit into
Twigpine:mainfrom
auriti:fix/profile-file-permissions

Conversation

@auriti

@auriti auriti commented Apr 1, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Sets file permissions to 0600 (owner read/write only) when writing .openclaude-profile.json
  • The profile file may contain API keys in plain text. Without explicit permissions, writeFileSync defaults to the process umask — on systems with permissive umask (0022), the file is world-readable (644), exposing credentials to other local users

Changes

1 line changed in scripts/provider-bootstrap.ts.

Relates to

#24

The profile file may contain API keys (OPENAI_API_KEY, CODEX_API_KEY,
GEMINI_API_KEY) in plain text. Without explicit permissions, writeFileSync
uses the process umask — on systems with permissive umask (0022), the file
is world-readable (644), exposing credentials to other users.

Relates to Twigpine#24

Co-Authored-By: Juan Camilo <juancamilo.auriti@gmail.com>
@kevincodex1
kevincodex1 merged commit 5fae22a into Twigpine:main Apr 2, 2026
euxaristia pushed a commit to euxaristia/openclaude that referenced this pull request Apr 13, 2026
fix: restrict .openclaude-profile.json to owner-only permissions (0600)
reymaster pushed a commit to reymaster/openclaude that referenced this pull request May 5, 2026
fix: restrict .openclaude-profile.json to owner-only permissions (0600)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants