Bash history settings

By default, bash keeps 500 to 2,000 commands, forgets those of a terminal that crashes, and lets the last terminal closed overwrite the others. Choose better, and paste the block at the end of ~/.bashrc.

Size
What is kept
Timestamps

    
Several terminals

For the end of ~/.bashrc

    

At the end of the file, so that these lines win over those already there (Debian’s ~/.bashrc sets HISTSIZE=1000). Takes effect in new terminals.

Useful with it

Ctrl+R
Search the history as you type; Ctrl+R again for the previous match.
history 20, history | grep ssh
The last 20 commands; the commands containing ssh.
history -d 1042
Remove entry 1042 (a password typed by mistake), then history -w to rewrite the file.

Transparency

The block is written in your browser, by the scripts listed below. Nothing you type leaves this page.

Enforced by your browser
This page's Content Security Policy allows a single destination, the site's audience measurement (connect-src https://stats.r-no.fr, see below), and forbids any form submission (form-action 'none'), so even a bug could not send what you type anywhere. You can read the policy at the top of the page source.
Audience measurement
Like every page of the site, this one counts its visit with Umami, installed on R-no’s own server (stats.r-no.fr). It receives the address of the page, without parameters or anchor, the site you came from (its domain only), your browser, system, language and screen size, and the country, region and city deduced from your IP address, which is not kept. It never receives what you type, nor the result of the tool. No cookie, nothing stored in your browser; if your browser asks not to be tracked (Do Not Track), nothing is measured. The data is erased after 25 months.
  • /commun/mesure.js: the filter applied before each sending, written for R-no Toolbox. 1.4 kB
    SHA-256 225eec74fd12623d82fc05ee7d222be629ce454d081c129e8d1e249ed37ee716
  • https://stats.r-no.fr/m.js: Umami’s tracker, open source (MIT), served by the measurement server. Its fingerprint is not shown here: it changes with each version of Umami, and you cannot check from your browser that it is the published code. For that part, you have to trust R-no.
What is stored
No cookie, and nothing in the address. What you type is never stored: it disappears when you reload or close the page. Your language is given by the address itself (/en/ or /fr/): nothing is stored to remember it. Like any website, the server records the download of the page and its files in its access logs (IP address, date and time, address requested, browser name). It never receives what you type.
Code that runs here
  • app.js: the writing of the block and of its warnings, written for R-no Toolbox. Not minified, no third-party library. 10.8 kB
    SHA-256 787194e9696ded956151413ca3d01eed0c3449a3dc920dc3bea1a457adc71891
  • textes.js: the French messages of the tool, shown by its script (the rest of the French page is written into its HTML when the site is built). It only defines texts, with no logic. 9.1 kB
    SHA-256 047acad1c289f790c97b8611bd4d0a6823af3f29b2656472c61d35e335ae40b1
  • /commun/langue.js: the language helper, the same on every page of the site. It reads the language of the page and gives the tool its messages in that language. It stores nothing. 1.6 kB
    SHA-256 80f76f69773ef628d36d09bf8387cfedebda4529210d7120649b6f5603310631
Before you paste
This page only writes text: it runs nothing, neither here nor on your machine. What you paste into a terminal or a configuration file runs with your rights, so read it first. The code it writes downloads nothing and calls no outside service.
How it was checked
Blocks with every option were loaded twice into bash 5.2 (as when ~/.bashrc is read again): the variables hold the expected values, PROMPT_COMMAND keeps what was there and does not grow, and the blocks pass ShellCheck.
Check it yourself
Download a script and compare its fingerprint with the one above:
curl -s https://r-no.fr/bash/history/app.js | shasum -a 256
Limits
Bash only: zsh (the default shell of macOS) has its own settings (HISTSIZE, SAVEHIST, setopt SHARE_HISTORY). The preview of the timestamp knows the common strftime codes only. The history is a plain text file readable by your account: it is not a safe place for secrets, whatever the settings.