Skip to content

security(sdk): codegen takes the admin token as a CLI argument, exposing it to ps and shell history #528

Description

@EricAndrechek

Area: sdk · codegen CLI — security · found via a codebase read of the TypeScript codegen (prompted by PR #434 deleting the Go copy for this defect class)

Expected: A credential the docs themselves describe as admin-role has some way in that does not land in the process table or in shell history.

Actual: --auth / -a is read straight from process.argv (clients/ts/src/cli/codegen.ts:38-40) and is the only way to supply a token (:185 is the sole consumer). There is no environment-variable fallback, no stdin, no file. And docs/src/content/docs/sdk/reference.md:136 — live on the public docs site — instructs exactly this:

Codegen reads /v1/ops/schema, which is admin-only. Against a non-dev server, pass an admin-role token with --auth <jwt> or the request is denied with 403.

Impact: On a shared or CI host, every local user can read the admin JWT out of ps for the life of the process; on a developer machine it is written verbatim into ~/.zsh_history. /v1/ops/schema is admin-gated, so this is the highest-privilege credential the deployment has. The wavehouse-codegen bin ships in @wavehouse/sdk 0.1.1, so the exposure is in the published artifact and the published page teaches the exposing invocation.

Note: the CLI also calls global fetch directly (:187) instead of going through the SDK's own request path, so the timeout and retry handling in clients/ts/src/http.ts do not apply to this authenticated request.

Related: #468, #478, #228


From a codebase read of the TypeScript codegen CLI (pm-triage routine); validated by code-read against 7b3c25e on 2026-08-28.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/authAuthentication: tokens, JWT/JWKS, keys, token expiry/revocationarea/sdkTypeScript SDK (clients/ts/)securitySecurity-sensitive issue or fix

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions