Two security-scanning findings on release/v3.8.6:
- Secret-scanning alert 7 (google_api_key): the windsurf login-fix design spec
embedded the literal public Firebase Web API key on two lines. Firebase Web
API keys are non-sensitive by design (they identify the project; access is
gated by Firebase Security Rules + key restrictions), but the literal trips
secret scanning. Redacted to a placeholder; the embedded default still goes
through resolvePublicCred per rule #11.
- Code-scanning alert 261 (js/insufficient-password-hash): tokenCacheKey() uses
SHA-256 to derive an in-memory cache key from the session token, not for
password-at-rest storage. Added a comment documenting why CWE-916 KDFs do not
apply (false positive).
Two-phase plan to fix the broken Windsurf OAuth flow:
- Phase 1: drop the dead app.devin.ai/editor/signin PKCE path, promote
import-token from windsurf.com/show-auth-token as the primary path
- Phase 2: port Firebase OAuth + RegisterUser flow from
fendoushaonian/WindSurf-gRPC-API for full browser-based automation
Spec only - no code changes yet.