You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Opening a file directly from the command line and pasting in insert mode briefly flash the non-cloaked values #25
Hi, I have noticed a few bugs when using cloak.nvim which lead to leaking sensitive values, this is critical since a lot of online content can be played back in time.
Opening files directly
When opening a file directly using neovim filename there is a brief flash of unmasked values
CleanShot.2025-02-19.at.22.44.45.mp4
Pasting content inside insert mode
When trying to copy-paste content in insert mode as for example using cmd+v, there is brief flash of unmasked value
CleanShot.2025-02-19.at.22.50.11.mp4
You can take a look at the implementation from my plugin - ecolog.nvim, It can be used as a nearly drop-in replacement for cloak.nvim for masking sensitive data, it provides all-in-one toolkit to work with environment variables and .env files. You can take a look at the comparisons table
changed the title [-][Bugs]: Cloak.nvim leaks sensitive values[/-][+]Opening a file directly from the command line and pasting in insert mode briefly flash the non-cloaked values[/+]on Mar 5, 2025
Hi, I have noticed a few bugs when using
cloak.nvimwhich lead to leaking sensitive values, this is critical since a lot of online content can be played back in time.Opening files directly
When opening a file directly using
neovim filenamethere is a brief flash of unmasked valuesCleanShot.2025-02-19.at.22.44.45.mp4
Pasting content inside insert mode
When trying to copy-paste content in insert mode as for example using
cmd+v, there is brief flash of unmasked valueCleanShot.2025-02-19.at.22.50.11.mp4
You can take a look at the implementation from my plugin - ecolog.nvim, It can be used as a nearly drop-in replacement for
cloak.nvimfor masking sensitive data, it provides all-in-one toolkit to work with environment variables and.envfiles. You can take a look at the comparisons table