Skip to content

feat(auth-curl): forward arbitrary curl flags to underlying curl - #6

Merged
pchuri merged 1 commit into
mainfrom
fm/authcurl-passthrough-w1
Jul 26, 2026
Merged

pchuri merged 1 commit into
mainfrom
fm/authcurl-passthrough-w1

Conversation

@pchuri

@pchuri pchuri commented Jul 26, 2026

Copy link
Copy Markdown
Owner

What

Makes auth-curl a faithful curl wrapper by forwarding any curl flag it does not itself consume to the underlying curl invocation, instead of rejecting it.

Before, auth-curl used a fixed commander option set, so ordinary curl flags failed:

$ auth-curl --max-time 25 -sL "$URL"
error: unknown option '-sL'   # exit 1

This broke generated checkers that emit curl-style flags (-sL, --retry, --connect-timeout, --http2, …), even though auth-curl advertises itself as "curl with automatic Chrome cookie authentication".

How

  • Enable commander allowUnknownOption(true). Commander already strips known auth-curl options and their values from program.args, leaving exactly the unknown flags, their values, and the URL — in original order.
  • Split those leftovers into the request URL (detected as the last URL-like token, matching the usual auth-curl [flags] URL ordering) and the passthrough flags. Commander's positional <url> is unreliable once unknown flags are present, so we derive the URL ourselves.
  • Forward the passthrough tokens into the built curl command, in order, before the URL — after auth-curl's own cookie/header injection and translated options, so nothing is double-passed.
  • Security: every forwarded token is single-quoted (' -> '\'') before being joined into the shell string handed to execSync, so passthrough can never break out of curl's argv (no shell injection). URL handling is unchanged.

Preserved exactly as before: automatic Chrome cookie injection, default headers, and all first-class options (-o, -H, -X, -d, --json, --follow-redirects, --insecure, --max-time, --connect-timeout, -v, -V, -h). Only previously-rejected unknown flags change from "error" to "forwarded".

Drive-by fix (called out for review)

While adding the required "existing options unchanged" regression test, I found a pre-existing latent crash: -H was declared with a [] default but no collector, so commander stored it as a string and options.header.forEach(...) threw forEach is not a function on any -H use. Added the standard collector so the documented multi--H usage works. Flagging it here since it's technically outside pure passthrough — happy to split it out if preferred.

Tests (tests/auth-curl.test.ts)

  • -sL forwarded; URL preserved.
  • --max-time 25 -sL <url> together — both reach curl, URL preserved.
  • Unknown long flag with value (--retry 3) forwarded with value, in order.
  • Passthrough cannot break out of curl argv (injection attempt stays single-quoted).
  • Existing option handling unchanged (-H, -X, -d, --json, -o).
  • Help lists first-class options and notes other curl flags pass through.

Full suite: 44/44 pass; build, type-check, and lint (0 errors) green. Verified end-to-end against a live URL (--max-time 15 -sL --retry 1) returning exit 0.

Note: the security check is being migrated to osv-scanner in a separate PR (#5); a red security for unrelated dependency reasons is expected — the test checks must pass.

🤖 Generated with Claude Code

auth-curl advertises itself as "curl with automatic Chrome cookie
authentication", but it only accepted a curated option subset, so
ordinary curl flags (e.g. `-sL`, `--retry`) failed with
"unknown option" and exit 1. Generated checkers that use curl-style
flags like `auth-curl --max-time 25 -sL "$URL"` broke.

Enable `allowUnknownOption` and forward every token commander does not
consume (unknown flags + their values) to curl, in order. The request
URL is detected from the leftover tokens (last URL-like token) instead
of commander's positional, which is unreliable once unknown flags are
present. Each forwarded token is single-quoted before joining into the
shell command, so passthrough can never break out of curl's argv.

Also fix a latent crash: `-H` was declared with a `[]` default but no
collector, so commander stored a string and `options.header.forEach`
threw on any `-H` use. Add the standard collector so the documented
multi-header usage works, keeping first-class option handling intact.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@pchuri
pchuri merged commit 6739734 into main Jul 26, 2026
4 checks passed
github-actions Bot pushed a commit that referenced this pull request Jul 26, 2026
# [1.2.0](v1.1.1...v1.2.0) (2026-07-26)

### Bug Fixes

* **decryptor:** correct macOS v10 cookie decryption (wrong key + M130 domain hash) ([#3](#3)) ([f4f6ed5](f4f6ed5))

### Features

* **auth-curl:** add --max-time and --connect-timeout passthrough to curl ([#4](#4)) ([5e46715](5e46715))
* **auth-curl:** forward unknown curl flags to the underlying curl ([#6](#6)) ([6739734](6739734))
@github-actions

Copy link
Copy Markdown

🎉 This PR is included in version 1.2.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant