fix(cli): secure configuration previews and atomic writes - #14381
Merged
diegosouzapw merged 4 commits intoSep 24, 2026
Merged
Conversation
diegosouzapw
marked this pull request as ready for review
September 21, 2026 22:09
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Status: INCOMPLETE / INFRA — CI validation requested, not merge-ready
This is the configuration-security slice of the approved Relay CLI completion plan. It preserves the container write guard and does not merge or deploy anything.
Changes
Consumer audit
A bounded literal/constructed-path audit of src, bin, electron, open-sse, packages and scripts found no executable first-party caller of the generic config/apply endpoints. Dashboard cards use per-tool settings APIs; manual-copy configuration is built locally. CLI configure delegates to local setup recipes. Generated agent-skill documentation was a real consumer and is updated here.
External clients using the old apiKey query must migrate to the documented header. Clients must send original toolId/baseUrl/apiKey/model inputs to apply, not replay redacted response content.
Validation
Open release-health issue: #13866 (reported docs/env hard failure and release ratchet drift). This candidate does not claim that the release base or this candidate is globally green.
No real credentials or temporary hook changes are committed. Final-parent-directory adversary protection is not claimed. Owner review and merge remain required.