From ff0d1bc1b855fe905e3c6fd40d3a49772130cd24 Mon Sep 17 00:00:00 2001 From: Daniel Han Date: Thu, 7 May 2026 03:27:42 +0000 Subject: [PATCH] CI(security): random-generated passwords in every workflow (no hardcoded creds) studio-ui-smoke.yml was the last holdout still using hardcoded rotated passwords (CIUiSmoke12345! / CIUiSmoke67890!). Generate them per-run via python -c 'import secrets; print(secrets.token_urlsafe(16))' and mask them into the log via GitHub Actions' ::add-mask::, matching the pattern already used in studio-inference-smoke.yml. If a workflow ever gets compromised (malicious dependency, leaked GITHUB_TOKEN, supply-chain attack on a pinned action), the rotated password is now unique to that single job run and is never readable from log output. An attacker cannot replay a hardcoded credential against a future / parallel Studio install elsewhere. --- .github/workflows/studio-ui-smoke.yml | 21 ++++++++++++++------- 1 file changed, 14 insertions(+), 7 deletions(-) diff --git a/.github/workflows/studio-ui-smoke.yml b/.github/workflows/studio-ui-smoke.yml index 497f4127ba..f3bfcdb6f0 100644 --- a/.github/workflows/studio-ui-smoke.yml +++ b/.github/workflows/studio-ui-smoke.yml @@ -123,16 +123,23 @@ jobs: # the JWT it got from change-password. So the only thing we # have to hand it is the bootstrap password (so it can verify # post-rotation that the OLD bootstrap pw now returns 401). + # + # NEW + NEW2 are generated freshly per CI run via secrets.token_urlsafe + # rather than hardcoded. If a workflow gets compromised, the + # attacker can't replay a known-good rotated password against + # any future / parallel Studio install -- the rotated value + # only ever exists for the lifetime of this single job, masked + # in the log via ::add-mask::. run: | OLD=$(cat ~/.unsloth/studio/auth/.bootstrap_password) + NEW="CIUi-$(python -c 'import secrets; print(secrets.token_urlsafe(16))')" + NEW2="CIUi-$(python -c 'import secrets; print(secrets.token_urlsafe(16))')" echo "::add-mask::$OLD" - echo "STUDIO_OLD_PW=$OLD" >> "$GITHUB_ENV" - # Two distinct rotated passwords -- the UI rotates from - # bootstrap -> NEW, and a later "terminal" subprocess(curl) - # rotates NEW -> NEW2 to prove an out-of-band password - # change invalidates the previous credentials. - echo "STUDIO_NEW_PW=CIUiSmoke12345!" >> "$GITHUB_ENV" - echo "STUDIO_NEW2_PW=CIUiSmoke67890!" >> "$GITHUB_ENV" + echo "::add-mask::$NEW" + echo "::add-mask::$NEW2" + echo "STUDIO_OLD_PW=$OLD" >> "$GITHUB_ENV" + echo "STUDIO_NEW_PW=$NEW" >> "$GITHUB_ENV" + echo "STUDIO_NEW2_PW=$NEW2" >> "$GITHUB_ENV" - name: Drive the chat UI with Playwright env: