Repository navigation
feat(auth-curl): forward arbitrary curl flags to underlying curl - #6
Merged
Merged
Conversation
auth-curl advertises itself as "curl with automatic Chrome cookie authentication", but it only accepted a curated option subset, so ordinary curl flags (e.g. `-sL`, `--retry`) failed with "unknown option" and exit 1. Generated checkers that use curl-style flags like `auth-curl --max-time 25 -sL "$URL"` broke. Enable `allowUnknownOption` and forward every token commander does not consume (unknown flags + their values) to curl, in order. The request URL is detected from the leftover tokens (last URL-like token) instead of commander's positional, which is unreliable once unknown flags are present. Each forwarded token is single-quoted before joining into the shell command, so passthrough can never break out of curl's argv. Also fix a latent crash: `-H` was declared with a `[]` default but no collector, so commander stored a string and `options.header.forEach` threw on any `-H` use. Add the standard collector so the documented multi-header usage works, keeping first-class option handling intact. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
github-actions Bot
pushed a commit
that referenced
this pull request
Jul 26, 2026
# [1.2.0](v1.1.1...v1.2.0) (2026-07-26) ### Bug Fixes * **decryptor:** correct macOS v10 cookie decryption (wrong key + M130 domain hash) ([#3](#3)) ([f4f6ed5](f4f6ed5)) ### Features * **auth-curl:** add --max-time and --connect-timeout passthrough to curl ([#4](#4)) ([5e46715](5e46715)) * **auth-curl:** forward unknown curl flags to the underlying curl ([#6](#6)) ([6739734](6739734))
|
🎉 This PR is included in version 1.2.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Makes
auth-curla faithful curl wrapper by forwarding any curl flag it does not itself consume to the underlyingcurlinvocation, instead of rejecting it.Before,
auth-curlused a fixed commander option set, so ordinary curl flags failed:This broke generated checkers that emit curl-style flags (
-sL,--retry,--connect-timeout,--http2, …), even thoughauth-curladvertises itself as "curl with automatic Chrome cookie authentication".How
allowUnknownOption(true). Commander already strips known auth-curl options and their values fromprogram.args, leaving exactly the unknown flags, their values, and the URL — in original order.auth-curl [flags] URLordering) and the passthrough flags. Commander's positional<url>is unreliable once unknown flags are present, so we derive the URL ourselves.' -> '\'') before being joined into the shell string handed toexecSync, so passthrough can never break out of curl's argv (no shell injection). URL handling is unchanged.Preserved exactly as before: automatic Chrome cookie injection, default headers, and all first-class options (
-o,-H,-X,-d,--json,--follow-redirects,--insecure,--max-time,--connect-timeout,-v,-V,-h). Only previously-rejected unknown flags change from "error" to "forwarded".Drive-by fix (called out for review)
While adding the required "existing options unchanged" regression test, I found a pre-existing latent crash:
-Hwas declared with a[]default but no collector, so commander stored it as a string andoptions.header.forEach(...)threwforEach is not a functionon any-Huse. Added the standard collector so the documented multi--Husage works. Flagging it here since it's technically outside pure passthrough — happy to split it out if preferred.Tests (
tests/auth-curl.test.ts)-sLforwarded; URL preserved.--max-time 25 -sL <url>together — both reach curl, URL preserved.--retry 3) forwarded with value, in order.-H,-X,-d,--json,-o).Full suite: 44/44 pass;
build,type-check, andlint(0 errors) green. Verified end-to-end against a live URL (--max-time 15 -sL --retry 1) returning exit 0.🤖 Generated with Claude Code