Credentials. The remote cache URL is the only place to put credentials, so tokens end up in its query string or user info. To keep the token out of vite.config.*, the URL comes from VP_REMOTE_CACHE_URL, and vp run passes every VP_* variable through to the processes tasks spawn. Every tool and script a task runs can read the token.
Env value hashes. Each tracked env value is hashed on its own with unsalted SHA-256, and those hashes are part of the key sent to the server. Anyone who can read the remote cache can recover short or guessable values, such as short tokens or passwords, by brute force.
Expected: credentials can be supplied separately from the URL, for example as a token sent in an Authorization header, and aren't passed to task processes. The server can't recover individual env values from what it stores.
Affects remote cache configuration (#727) and the key format (#755).
Credentials. The remote cache URL is the only place to put credentials, so tokens end up in its query string or user info. To keep the token out of
vite.config.*, the URL comes fromVP_REMOTE_CACHE_URL, andvp runpasses everyVP_*variable through to the processes tasks spawn. Every tool and script a task runs can read the token.Env value hashes. Each tracked env value is hashed on its own with unsalted SHA-256, and those hashes are part of the key sent to the server. Anyone who can read the remote cache can recover short or guessable values, such as short tokens or passwords, by brute force.
Expected: credentials can be supplied separately from the URL, for example as a token sent in an
Authorizationheader, and aren't passed to task processes. The server can't recover individual env values from what it stores.Affects remote cache configuration (#727) and the key format (#755).