harness / harness/harness-cli

Potential Conflict with Generic Secret Path Name in ~/.secrets.json

Open
#74 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Go
Stars
25
Forks
25
PR merge metrics
No merged PRs in 30d

Description

The current secret path defined in the Harness CLI uses a very generic file name (~/.secrets.json), which has a potential risk of conflicting with other tools (or personal notes) that might use the same file name.

const SECRETS_STORE_PATH = ".secrets.json"

Is there a specific reason for choosing such a generic name for this file?

To reduce the risk of conflicts, it would be beneficial to store this file in a dedicated directory, such as ~/.harness/.secrets.json.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Search the Go codebase for SECRETS_STORE_PATH and inspect how the secret file path is constructed and used. Confirm whether the path can move under ~/.harness while preserving existing secret handling, then update or add relevant tests so the dedicated path is verified.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
cli
Issue type
Feature
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.