fix(dispatch): pass injected apiKeyHelper via 0600 file, not argv

main

Commit

alishakawaguchi2mo ago

The apiKeyHelper injected for auth was passed as an inline --settings JSON string, which lands in the process argv (visible via ps, /proc/<pid>/cmdline, and EDR/process-monitoring tooling). apiKeyHelper can embed a literal API key, so this widened credential exposure beyond the permission-restricted settings.json (trail #884 finding).

Write the minimal {"apiKeyHelper": ...} settings to a 0600 temp file (os.CreateTemp) and pass it as --settings <path>, removing it after the call. The key-bearing content stays off argv and keeps settings.json-equivalent file protection. --settings still fully isolates the call: no user hooks or permissions are loaded.

Verified end-to-end: during a real dispatch --local the spawned claude argv shows only "--settings <temp path>" (grep for the key in argv finds nothing), auth still resolves via the helper, the temp file is cleaned up afterward, and subscription/env-var auth still work. Unit tests assert --settings is a path (not inline JSON), the file is 0600 containing only apiKeyHelper, and cleanup removes it.

Addresses trail #884 review finding.

Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com Claude-Session: https://claude.ai/code/session_012QYA1kFFwDTbR8cZQQkb8N Entire-Checkpoint: 01KXPGXGCAR88KF07Y31PVCVYT