Skip to content

Review credential and cache handling before wider release #3

@rain2day

Description

@rain2day

Goal

Do a focused privacy/security review before promoting the project beyond early OSS status.

Review Areas

  • Codex auth read and refresh write-back.
  • Claude file, environment, and Keychain credential paths.
  • Local cache contents under Application Support.
  • Diagnostic logging to /tmp/codex-usage-halo.log.
  • Provider backoff and refresh behavior.

Done When

  • docs/PRIVACY.md reflects the verified behavior.
  • SECURITY.md reporting guidance is still accurate.
  • No logs or cache paths include raw tokens or full credential payloads.

Metadata

Metadata

Assignees

No one assigned

    Labels

    privacyCredential access, cache contents, logging, or network behavior

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions