Skip to content

Harden URL opening, config file permissions, and SDK version - #31

Merged
TristanH merged 1 commit into
masterfrom
security-fixes
Oct 4, 2026
Merged

TristanH merged 1 commit into
masterfrom
security-fixes

Conversation

@TristanH

@TristanH TristanH commented Oct 4, 2026

Copy link
Copy Markdown
Member

Summary

  • TUI: open result URLs with the open package (already used in auth.ts) instead of building a shell command, and only open http:/https: URLs.
  • Config: write ~/.readwise-cli.json with 0600 permissions, since it holds OAuth tokens and the client secret. A chmod after writing also tightens files created by older versions.
  • Deps: change @modelcontextprotocol/sdk from "latest" to "^1.26.0", matching the lockfile, so global installs don't pick up arbitrary new versions.

Testing

  • npm test and npm run build pass.
  • Checked with a temp HOME: a new config file is created as 600, and an existing 644 file becomes 600 after a save.
  • Manually press Enter on a result card in the TUI to confirm URLs still open in the browser.

🤖 Generated with Claude Code

- TUI: open result URLs via the `open` package instead of a shell
  command, and only open http(s) URLs.
- Config: write ~/.readwise-cli.json with 0600 permissions and tighten
  existing files on save.
- Pin @modelcontextprotocol/sdk to ^1.26.0 instead of "latest".

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@TristanH
TristanH merged commit 8a289d4 into master Oct 4, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant