{"record":{"id":"00fbc862036187af","repo":"Hmbown/CodeWhale","slug":"current-windows-user-token-has-no-sid-report","errorCode":null,"errorMessage":"current Windows user token has no SID","messagePattern":"current Windows user token has no SID","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"crates/tui/src/tools/github/report.rs","lineNumber":1163,"sourceCode":"                GetTokenInformation(\n                    token,\n                    TokenUser,\n                    token_info.as_mut_ptr().cast(),\n                    needed,\n                    &mut needed,\n                )\n            } == 0\n            {\n                let error = std::io::Error::last_os_error();\n                // SAFETY: the token is owned on this error path.\n                unsafe { CloseHandle(token) };\n                return Err(error).context(\"reading current Windows user token information\");\n            }\n            let user = unsafe { &*token_info.as_ptr().cast::<TOKEN_USER>() };\n            if user.User.Sid.is_null() {\n                // SAFETY: the token is owned on this error path.\n                unsafe { CloseHandle(token) };\n                bail!(\"current Windows user token has no SID\");\n            }\n            Ok(Self { token, token_info })\n        }\n\n        fn sid(&self) -> windows_sys::Win32::Security::PSID {\n            use windows_sys::Win32::Security::TOKEN_USER;\n            // SAFETY: the aligned token buffer remains owned by `self`.\n            unsafe { (*self.token_info.as_ptr().cast::<TOKEN_USER>()).User.Sid }\n        }\n    }\n\n    #[cfg(windows)]\n    impl Drop for CurrentWindowsUser {\n        fn drop(&mut self) {\n            // SAFETY: `token` is owned by this guard and closed exactly once.\n            unsafe { windows_sys::Win32::Foundation::CloseHandle(self.token) };\n        }\n    }","sourceCodeStart":1145,"sourceCodeEnd":1181,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/73e0f67d83c59909b571efdfc88c4bc28c309cb1/crates/tui/src/tools/github/report.rs#L1145-L1181","documentation":"On Windows, the GitHub tool opens the current user's access token and reads its TOKEN_USER information to derive the user's SID. If the token carries no user SID (User.Sid is null), the handle is closed and this error is thrown, since SID-based owner filtering cannot proceed. The token handle is leaked-free by design on this path.","triggerScenarios":"Running the GitHub report tool on Windows in a context where GetTokenInformation succeeds but returns no SID — e.g. certain service accounts, impersonation contexts, or exotic token configurations.","commonSituations":"Running under a Windows service or scheduled task with an unusual token; sandboxed/restricted processes; antivirus or policy software stripping token user info.","solutions":["Run the tool under an interactive user account whose token has a normal user SID.","Check whether security policy or sandboxing is stripping token information and adjust it.","If only run on non-Windows platforms, skip this Windows-specific path or feature-detect it."],"exampleFix":null,"handlingStrategy":"fallback","validationCode":null,"typeGuard":null,"tryCatchPattern":"match ReportOwner::open() {\n    Ok(owner) => owner,\n    Err(e) if e.to_string().contains(\"no SID\") => {\n        // fall back to non-SID-based attribution or skip ownership filter\n        skip_sid_filter()\n    }\n    Err(e) => return Err(e),\n}","preventionTips":["Run under an interactive Windows user account, not a stripped service token.","Verify token integrity if security tooling may alter it.","Feature-detect SID availability before enabling SID-based filtering."],"tags":["windows","security","github"],"backgroundTag":"insufficient-permissions","analyzedSha":"73e0f67d83c59909b571efdfc88c4bc28c309cb1","analyzedAt":"2026-09-22T01:30:00.501Z","contentChangedAt":"2026-09-22T01:30:00.501Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}