Evidence record / pi-coding-agent
A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.
Authentication file mode set at creation time
What Changed
Introduced AUTH_FILE_WRITE_OPTIONS constant with mode 0o600 (owner read/write only) applied to all FileAuthStorageBackend writeFileSync() calls. Reduces the security window where auth files could exist with insecure permissions before subsequent chmod operations.
Operator Implication
Hardens credential storage by ensuring authentication files never briefly exist with world-readable permissions. Closes temporal window for permission escalation.
Receipt
Finding metadata
Run: 2026-06-03-weekly-digest-2026-05-28_2026-06-03-frontier-v0
Finding ID: 2026-06-02-pi-coding-agent-auth-file-permissions
Source links
Primary links, including exact changelog lines when available.
Versioned source: run artifact