Skip to content

fix: persist CLI credentials on headless Linux - #6

Merged
kody-bot merged 1 commit into
mainfrom
cursor/headless-linux-credentials-7664
Sep 14, 2026
Merged

kody-bot merged 1 commit into
mainfrom
cursor/headless-linux-credentials-7664

Conversation

@kentcdodds

Copy link
Copy Markdown
Owner

Problem

On headless Linux, kody login appeared to succeed but a reboot silently logged the user out. @napi-rs/keyring does not throw when Secret Service is missing — it uses the in-memory kernel keyring — so nothing was written under $XDG_CONFIG_HOME/kody. loadCredentials only fell back to that file when keyring get() threw; getPassword() returns null for a missing entry, so the fallback never ran.

Fixes #5

Fix

Product choice A: require a durable OS store; otherwise use the documented 0600 file.

  • Bump @napi-rs/keyring to ^2.1.0 and pin Linux to Secret Service ({ linux: { store: 'secret-service' } }). The constructor throws when that store is missing, so the existing file fallback fires. Kernel keyutils is not used.
  • If keyring get() returns null or stored data is invalid, load the file. Desktop Secret Service / macOS / Windows stay on the OS keychain.
  • Login already prints the file-path message when backendKind === 'file'.

Risk

Medium. Credential persistence, but it matches the README and does not dual-write tokens to disk when a real keychain exists. Affected users need one more kody login.

Verify

  • npm run validate (typecheck, tests, build)
  • On this headless Linux VM, resolveBackend chose the file store, save/load/delete round-tripped ~/.config/kody/credentials-kody.codes.json, and leftover smoke credentials were deleted
  • New store tests cover constructor-throw, set throw, keyring null, invalid keyring, leftover-file preference, and dual delete
Open in Web Open in Cursor 

Pin the Linux keyring to Secret Service so @napi-rs/keyring cannot silently
use the in-memory kernel keyring. When Secret Service is missing, and when
keyring get returns null, fall back to the documented 0600 file store.

Closes #5

Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
@kentcdodds
kentcdodds marked this pull request as ready for review September 14, 2026 18:03
@kentcdodds

Copy link
Copy Markdown
Owner Author

bugbot review

@cursor

cursor Bot commented Sep 14, 2026

Copy link
Copy Markdown

Skipping Bugbot: Bugbot is disabled for this repository. Visit the Bugbot dashboard to update your settings.

@kody-bot
kody-bot merged commit 2443d13 into main Sep 14, 2026
5 checks passed
@github-actions

Copy link
Copy Markdown

🎉 This PR is included in version 1.2.1 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Credentials silently lost on headless Linux: keyring backend never throws, file fallback never fires

3 participants