github / github/copilot-cli

Prompt mode `-p` doesn't respect allowed directories

Đang mở
#668 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
area:non-interactive area:permissions
Ngôn ngữ chính
Shell
Star
11.2k
Fork
1.9k
Merge trung bình
14 giờ 16 phút
Pull request đã merge (30 ngày)
6

Mô tả

### Describe the bug

When using `copilot` with the `-p` option, the current directory isn't checked against the allowed directories.

This seems like a big problem because one accidental invocation in the wrong place (like `$HOME`) potentially exposes a lot of private information with no confirmation to allow one to realize the mistake.

### Affected version

0.0.365 Commit: 76d0881

### Steps to reproduce the behavior

1. Create a test directory where Copilot doesn't have access to it or any parents already.
`mkdir test`
2. Change the current directory to the test directory.
`cd test`
3. Make a test file with potentially private content.
`echo "Private data!" > data.txt`
4. Check if Copilot can read the content.
`copilot -p "What are the files and their contents in the current directory?"`

### Expected behavior

Copilot should error in some way since the current directory was never approved for access.

### Additional context

As an aside, my output of the above command shows a misleading number of files found and lines read. Not sure what that's about.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.