git-remote-entire: address PR review on ENTIRE_TOKEN path

main

Commit

Soph3mo ago
  • Redact userinfo in CoreURLFromEnvToken error messages (u.Redacted()) so a malformed aud with credentials can't leak to stderr/logs.
  • Fail closed with a clear "ENTIRE_TOKEN is set but blank" message on a whitespace-only token instead of the raw JWT-parse error; truly empty is still treated as unset by the caller and falls back to context auth.
  • Rename "core" -> "login server" in resolveCreds doc comments.

Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com Entire-Checkpoint: b5f6f2ff8832

Checkpoints

ENTIRE_TOKEN Security and Validation Fixes

Claude CodeOpus 4.8[1m]
View session
Checkpoint 1