Gemini CLI patch blocks credential leakage by forcing HTTPS for auth provider
amelidev · ghdev · 2026-07-24
A GitHub pull request for google-gemini/gemini-cli adds an HTTPS enforcement check to GoogleCredentialsAuthProvider.
The change is meant to stop Application Default Credentials access and identity tokens from being sent over plain HTTP, reducing the risk of cleartext leakage and MITM interception.
Key points:
- Verifies that targetUrl uses https: during provider initialization
- Blocks high-privilege tokens, including broad-scope cloud-platform credentials, from going over HTTP
- Adds unit tests for both the auth provider and the leak-prevention path
The PR also documents how to run the targeted test files.
More from coding & agent
- Cheaper OpenAI Agents API alternative: sandbox service undercutting E2B by 46% — airesearch12 · 2026-09-11
- His agent kill switch ran for months before he found it was wired to nothing — AnvilandCode · 2026-09-11
- Kernel's Browser Agents Can Now Pay Online Using Aliases, Never Touching Card Data — jeff_weinstein · 2026-09-11
- OpenAI opens up agent sandboxes: BYO or pick from Cloudflare, E2B, Modal, Vercel and more — threepointone · 2026-09-11
- SocialCrawl MCP lets agents search Reddit, YouTube, TikTok, X with one API key — dooddyman · 2026-09-11
- Astra builds a surprisingly polished Catan game in three.js, reusing past UI and 3D assets — FinanceYF5 · 2026-09-11