Skip to content

fix(cli): respect global environment variable allowlist#24767

Merged
scidomino merged 1 commit intomainfrom
tomm_allowed_env
Apr 6, 2026
Merged

fix(cli): respect global environment variable allowlist#24767
scidomino merged 1 commit intomainfrom
tomm_allowed_env

Conversation

@scidomino
Copy link
Copy Markdown
Collaborator

Summary

This PR fixes a bug where the global allowlist for environment variable redaction was completely ignored during configuration loading.

Details

The settings.security.environmentVariableRedaction.allowed array is defined in the settingsSchema.ts file, and the core Config object accepts an allowedEnvironmentVariables parameter. However, loadCliConfig in packages/cli/src/config/config.ts was not mapping the setting from settings.json into the Config constructor. This one-line fix maps the parsed setting so the global allowlist is respected.

Related Issues

Fixes #18302

How to Validate

  1. Add a sensitive key name (like MY_SECRET_TOKEN) to the security.environmentVariableRedaction.allowed array in your settings.json.
  2. Configure an MCP server in settings.json.
  3. Set the MY_SECRET_TOKEN environment variable on your system.
  4. Launch the CLI and verify that the unredacted token is successfully passed to the MCP server during discovery.

Pre-Merge Checklist

  • Updated relevant documentation and README (if needed)
  • Added/updated tests (if needed)
  • Noted breaking changes (if any)
  • Validated on required platforms/methods:
    • MacOS
      • npm run
      • npx
      • Docker
      • Podman
      • Seatbelt
    • Windows
      • npm run
      • npx
      • Docker
    • Linux
      • npm run
      • npx
      • Docker

@scidomino scidomino requested a review from a team as a code owner April 6, 2026 19:00
@gemini-code-assist
Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request addresses a configuration loading issue where the global allowlist for environment variable redaction was being ignored. By correctly mapping the setting from the configuration file to the internal application state, the system now properly respects user-defined exceptions for environment variable redaction.

Highlights

  • Environment Variable Redaction: Mapped the global allowlist from settings to the CLI configuration to ensure sensitive keys are correctly handled.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

@github-actions
Copy link
Copy Markdown

github-actions bot commented Apr 6, 2026

Size Change: +87 B (0%)

Total Size: 34 MB

Filename Size Change
./bundle/chunk-MN3FCVGY.js 0 B -3.15 MB (removed) 🏆
./bundle/chunk-VN7XS4EK.js 0 B -14.8 MB (removed) 🏆
./bundle/core-PX7UGXZO.js 0 B -45.2 kB (removed) 🏆
./bundle/devtoolsService-WBKKPDRA.js 0 B -28.4 kB (removed) 🏆
./bundle/interactiveCli-PVKNCILJ.js 0 B -1.64 MB (removed) 🏆
./bundle/oauth2-provider-ETHL5MB2.js 0 B -9.16 kB (removed) 🏆
./bundle/chunk-3XCCW4JT.js 14.8 MB +14.8 MB (new file) 🆕
./bundle/chunk-YPFUYF5O.js 3.15 MB +3.15 MB (new file) 🆕
./bundle/core-LLTLSBSA.js 45.2 kB +45.2 kB (new file) 🆕
./bundle/devtoolsService-24TQ7SHO.js 28.4 kB +28.4 kB (new file) 🆕
./bundle/interactiveCli-ODD7CBZJ.js 1.64 MB +1.64 MB (new file) 🆕
./bundle/oauth2-provider-3GI5NF34.js 9.16 kB +9.16 kB (new file) 🆕
ℹ️ View Unchanged
Filename Size Change
./bundle/bundled/third_party/index.js 8 MB 0 B
./bundle/chunk-34MYV7JD.js 2.45 kB 0 B
./bundle/chunk-5AUYMPVF.js 858 B 0 B
./bundle/chunk-5PS3AYFU.js 1.18 kB 0 B
./bundle/chunk-664ZODQF.js 124 kB 0 B
./bundle/chunk-DAHVX5MI.js 206 kB 0 B
./bundle/chunk-GFUOVHXW.js 1.96 MB 0 B
./bundle/chunk-IUUIT4SU.js 56.5 kB 0 B
./bundle/chunk-RJTRUG2J.js 39.8 kB 0 B
./bundle/devtools-36NN55EP.js 696 kB 0 B
./bundle/dist-T73EYRDX.js 356 B 0 B
./bundle/events-XB7DADIJ.js 418 B 0 B
./bundle/gemini.js 552 kB +91 B (+0.02%)
./bundle/getMachineId-bsd-TXG52NKR.js 1.55 kB 0 B
./bundle/getMachineId-darwin-7OE4DDZ6.js 1.55 kB 0 B
./bundle/getMachineId-linux-SHIFKOOX.js 1.34 kB 0 B
./bundle/getMachineId-unsupported-5U5DOEYY.js 1.06 kB 0 B
./bundle/getMachineId-win-6KLLGOI4.js 1.72 kB 0 B
./bundle/memoryDiscovery-ACCRGPX3.js 980 B 0 B
./bundle/multipart-parser-KPBZEGQU.js 11.7 kB 0 B
./bundle/node_modules/@google/gemini-cli-devtools/dist/client/main.js 222 kB 0 B
./bundle/node_modules/@google/gemini-cli-devtools/dist/src/_client-assets.js 229 kB 0 B
./bundle/node_modules/@google/gemini-cli-devtools/dist/src/index.js 13.4 kB 0 B
./bundle/node_modules/@google/gemini-cli-devtools/dist/src/types.js 132 B 0 B
./bundle/sandbox-macos-permissive-open.sb 890 B 0 B
./bundle/sandbox-macos-permissive-proxied.sb 1.31 kB 0 B
./bundle/sandbox-macos-restrictive-open.sb 3.36 kB 0 B
./bundle/sandbox-macos-restrictive-proxied.sb 3.56 kB 0 B
./bundle/sandbox-macos-strict-open.sb 4.82 kB 0 B
./bundle/sandbox-macos-strict-proxied.sb 5.02 kB 0 B
./bundle/src-QVCVGIUX.js 47 kB 0 B
./bundle/tree-sitter-7U6MW5PS.js 274 kB 0 B
./bundle/tree-sitter-bash-34ZGLXVX.js 1.84 MB 0 B

compressed-size-action

Copy link
Copy Markdown
Contributor

@jacob314 jacob314 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@scidomino scidomino enabled auto-merge April 6, 2026 19:04
Copy link
Copy Markdown
Contributor

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the CLI configuration loading logic in packages/cli/src/config/config.ts to include an allowedEnvironmentVariables property, which is mapped from the security settings for environment variable redaction. I have no feedback to provide as there are no review comments.

@gemini-cli gemini-cli bot added priority/p1 Important and should be addressed in the near term. area/security Issues related to security labels Apr 6, 2026
@scidomino scidomino added this pull request to the merge queue Apr 6, 2026
Merged via the queue into main with commit df67f97 Apr 6, 2026
30 checks passed
@scidomino scidomino deleted the tomm_allowed_env branch April 6, 2026 22:59
warrenzhu25 pushed a commit to warrenzhu25/gemini-cli that referenced this pull request Apr 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/security Issues related to security priority/p1 Important and should be addressed in the near term.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

security.environmentVariableRedaction.allowed broken

2 participants