Skip to content

Restore ban on browser-driven credential creation (v1.64.14.0)#44

Merged
time-attack merged 3 commits into
mainfrom
time-attack/appleship-credential-ban
Jul 24, 2026
Merged

Restore ban on browser-driven credential creation (v1.64.14.0)#44
time-attack merged 3 commits into
mainfrom
time-attack/appleship-credential-ban

Conversation

@time-attack

@time-attack time-attack commented Jul 24, 2026

Copy link
Copy Markdown
Owner

Live nimbus round 8: the run recommended driving account.apple.com via Aside to mint an app-specific password. The explicit credential-drive ban from v1.64.6.0 was lost in the v1.64.7.0 contract compression. Restored and widened: no browser drives for any password, key, or token. Legal ASP fallback defined: quote the real upload auth error verbatim, self-service generation + in-session masked keychain add, retry.

Test evidence: test:gstack2 gate green (parity 4,359).

🤖 Generated with Claude Code


Summary by cubic

Restores and widens the ban on browser-driven credential creation. Adds a safe, self-service ASP fallback for real upload auth errors.

  • Bug Fixes
    • Prohibit browser-driven creation of any password, key, or token (no Aside or agentic browser, any framing).
    • Define the only legal ASP fallback: quote the real upload auth error verbatim, user self-generates ASP, adds it via in-session masked keychain prompt (fastlane fastlane-credentials add --username <apple-id>), then retry.
    • Update guidance in skills/ship/references/APPLE-RELEASE.md and regenerate scripts/gstack2/generate-skill-tree.ts to enforce the policy.
    • Bump version to 1.64.14.0 and add CHANGELOG entry.

Written for commit 0a9d16e. Summary will update on new commits.

Review in cubic

Sinabina and others added 3 commits July 24, 2026 10:08
Lost in the v1.64.7.0 compression. Legal ASP fallback: verbatim error,
in-session masked keychain add, retry. No Aside for credentials, ever.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@time-attack
time-attack merged commit 9b5ad8a into main Jul 24, 2026
0 of 2 checks passed
@cursor

cursor Bot commented Jul 24, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant