github / github/copilot-cli

Config corruption: PowerShell variable syntax in URLs crashes CLI on launch

未關閉
#2,195 0 則留言 1 個 reaction 已指派 0 人 在 GitHub 檢視
area:configuration area:platform-windows
主要語言
Shell
星號
11.2k
分支
1.9k
平均合併
14 小時 16 分鐘
30 天內合併 PR
6

描述

### Describe the bug

When running PowerShell commands that contain REST API URLs with variable interpolation (e.g. https://${bmcIp}/redfish/v1/...), the CLI's URL approval mechanism captures the unresolved PowerShell template as a literal string and
persists it to ~/.copilot/config.json under allowed_urls.

On next launch, the CLI fails to parse these malformed URLs and silently exits with code 1 — no error message, no log. The only fix is manually editing config.json to remove the bad entries.

Repro:

1. In a session, have the agent run PowerShell with URLs containing $variable syntax (e.g. iDRAC Redfish calls)
2. CLI prompts to approve the URL — the raw https://$ template gets saved to config
3. Exit and relaunch → CLI silently crashes

Corrupted config.json looked like:

"allowed_urls": [
"https://dev.azure.com",
"https://$",
"https://$($n.ip)/redfish/v1/Dell/Managers/..."
]

### Affected version

_No response_

### Steps to reproduce the behavior

1. In a Copilot CLI session, run PowerShell commands containing Redfish/REST API URLs with PowerShell variable interpolation, e.g.: Invoke-RestMethod -Uri "https://${bmcIp}/redfish/v1/Systems/System.Embedded.1"
2. The CLI's URL approval mechanism captures the unresolved template (https://$, https://$($n.IP)/...) and persists them into ~/.copilot/config.json under allowed_urls
3. On next launch, the CLI fails to parse the malformed URLs and silently exits with code 1

### Expected behavior

- URLs with $ variable syntax should be sanitized/rejected before persisting to config
- At minimum, malformed allowed_urls entries should not crash the CLI on startup

### Additional context

- config.json gets poisoned with entries like https://$ and https://$($n.ip)/redfish/...
- CLI silently fails to launch (exit code 1, no error message)
- User must manually edit config.json to remove the bad entries

貢獻指南

開啟貢獻指南

研究方向

Start with the CLI's URL approval mechanism and the allowed_urls entries in ~/.copilot/config.json, then reproduce startup using the malformed https://$ values described in the issue. Done means PowerShell variable templates are rejected or sanitized before persistence, and malformed allowed_urls entries no longer cause a silent launch failure.

由索引模型根據 Issue 內容生成。

評估

技術堆疊
powershell
領域
cli
Issue 類型
缺陷
難度
3/5
預估耗時
1-2 天
活躍度
停滯
描述清晰度
基本清楚
新手友好度
45/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。