Stop credential tokens leaking into usage output

main

Commit

Soph3mo ago

Token flags registered their env value as the pflag default (e.g. StringVar(&auth.Token, "source-token", envOr("GITSYNC_SOURCE_TOKEN", ""))). pflag prints non-empty defaults in --help, and the unknown-flag fallback in main.go dumps the full usage block to stderr — so a typo'd flag in a CI job with GITSYNC_*_TOKEN set wrote the credential into CI logs.

Register secret flags (source/target token + bearer-token, including the inlined ones in convert-sha256) with empty defaults and apply the env value after parsing via a PreRunE hook, only when the flag was not given explicitly. An explicit flag still wins over the environment.

Add chainPreRunE so independent flag helpers can each attach post-parse logic without clobbering one another, and route allRefsFlag through it too.

Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com Entire-Checkpoint: 409a151aeced

Checkpoints

just remove .clawpatch from the commit but then just delete the folder, we don't need to keep it

Claude CodeOpus 4.8[1m]
View session
Checkpoint 1

Review the code changes against the base branch 'main'. The merge base commit for this comparison is 368750cee35f31935640a34ad199e889fc60f1a8. Run `git diff 368750cee35f31935640a34ad199e889fc60f1a8` t

CodexGPT-5.5
View session
Checkpoint 1