{"record":{"id":"1b74531487d6a186","repo":"JuliusBrussee/caveman","slug":"auth-token-in-s-is-ignored-the-inbound-token-is-read-only","errorCode":null,"errorMessage":"auth_token: in %s is ignored — the inbound token is read only from the CAVEMAN_AUTH_TOKEN environment variable; remove the key","messagePattern":"auth_token: in (.+?) is ignored — the inbound token is read only from the CAVEMAN_AUTH_TOKEN environment variable; remove the key","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"proxy/internal/config/config.go","lineNumber":173,"sourceCode":"// default config (record mode on 127.0.0.1:8787) rather than an error: a bare\n// `caveman start` with no config file is a valid record-only session.\nfunc Load(path string) (Config, error) {\n\tcfg := Config{}\n\traw, err := os.ReadFile(path)\n\tswitch {\n\tcase os.IsNotExist(err):\n\t\t// no file — defaults only\n\tcase err != nil:\n\t\treturn cfg, err\n\tdefault:\n\t\tif err := yaml.Unmarshal(raw, &cfg); err != nil {\n\t\t\treturn cfg, err\n\t\t}\n\t}\n\tif strings.TrimSpace(cfg.AuthTokenYAML) != \"\" {\n\t\t// Never echo the value: it reached a file on disk, but this error reaches\n\t\t// the proxy log.\n\t\treturn Config{}, fmt.Errorf(\"auth_token: in %s is ignored — the inbound token is read only from the CAVEMAN_AUTH_TOKEN environment variable; remove the key\", path)\n\t}\n\tcfg = cfg.withDefaults()\n\tif err := validateAuthToken(cfg.AuthToken); err != nil {\n\t\treturn Config{}, err\n\t}\n\tif err := validateListen(cfg.Listen, cfg.AuthToken != \"\"); err != nil {\n\t\treturn Config{}, err\n\t}\n\tif err := cfg.validateCompat(); err != nil {\n\t\treturn Config{}, err\n\t}\n\tproxyFunc, err := parseUpstreamProxy(cfg.UpstreamProxy)\n\tif err != nil {\n\t\treturn Config{}, err\n\t}\n\tcfg.upstreamProxy, cfg.upstreamProxyParsed = proxyFunc, true\n\tif err := cfg.loadRootCAs(); err != nil {\n\t\treturn Config{}, err","sourceCodeStart":155,"sourceCodeEnd":191,"githubUrl":"https://github.com/JuliusBrussee/caveman/blob/3ee70a102609e550bd2e68004bf5990a9341c851/proxy/internal/config/config.go#L155-L191","documentation":"The caveman.yaml loader (proxy/internal/config/config.go:173) refuses to start when the config file contains an auth_token key. Inbound authentication is deliberately read only from the CAVEMAN_AUTH_TOKEN environment variable so the secret never persists to disk; a token found in YAML is treated as a hard configuration error and the file's value is never echoed to the log.","triggerScenarios":"Running 'caveman-proxy serve' (or status, via Load) with a caveman.yaml that has an auth_token: line — typically written by hand or by an older workflow — triggers this fail-fast error before the listener starts.","commonSituations":"Migrating from a version/agent that stored tokens in YAML; copying a config template that still lists auth_token; following outdated docs; a provisioning script writing secrets into the config file.","solutions":["Delete the auth_token key from caveman.yaml","Export CAVEMAN_AUTH_TOKEN=<token> in the proxy's environment instead","If you intentionally want no token, remove the key entirely rather than leaving it empty-stringed only if your YAML parser keeps it — ensure the parsed value is empty","Update provisioning scripts/templates so they inject the env var, not the YAML key"],"exampleFix":"// before (caveman.yaml)\nlisten: 127.0.0.1:8080\nauth_token: sk-secret-123\n// after (caveman.yaml)\nlisten: 127.0.0.1:8080\n# shell: export CAVEMAN_AUTH_TOKEN=sk-secret-123","handlingStrategy":"validation","validationCode":"func assertNoAuthTokenInYAML(t string) error {\n    var m map[string]any\n    if err := yaml.Unmarshal([]byte(t), &m); err != nil { return err }\n    if _, ok := m[\"auth_token\"]; ok {\n        return errors.New(\"remove auth_token from caveman.yaml; use CAVEMAN_AUTH_TOKEN env\")\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":"if _, err := config.Load(path); err != nil {\n    if strings.Contains(err.Error(), \"auth_token:\") {\n        logger.Error(\"config rejected: auth_token key present; use CAVEMAN_AUTH_TOKEN env var instead\")\n        os.Exit(1)\n    }\n    return err\n}","preventionTips":["Never write secrets into caveman.yaml; inject CAVEMAN_AUTH_TOKEN via the environment","Lint config templates for an auth_token key in CI","Update old provisioning scripts that predate the env-only rule"],"tags":["config","security","auth-token","yaml"],"backgroundTag":"unsupported-config-value","analyzedSha":"3ee70a102609e550bd2e68004bf5990a9341c851","analyzedAt":"2026-09-20T15:53:39.229Z","contentChangedAt":"2026-09-20T15:53:39.229Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}