feat(auth)!: make browser OAuth/PKCE the only credential source - #94
Merged
Merged
Conversation
Resolve() read PLIVO_AUTH_ID/PLIVO_AUTH_TOKEN ahead of the active profile, so a long-lived auth_token pasted into a shell profile or a CI secret bypassed the PKCE handshake entirely. Drop that branch: credentials now come only from a profile written by `plivo login`. Resolution order is --profile -> active profile. The "env" credSource is unreachable, so credentialHint() collapses to the profile case; it also now points at `plivo login --name`, since --profile selects a profile rather than naming one at login. Tests that exercised the env path are deleted; the ones that used it to supply credentials (safety_test's setFakeCreds, scripts/smoke.sh) write a throwaway profile into a temp HOME instead. USERPROFILE is set alongside HOME because os.UserHomeDir() reads it on the Windows smoke leg. BREAKING CHANGE: headless/CI callers that exported PLIVO_AUTH_ID and PLIVO_AUTH_TOKEN no longer authenticate. Such a host needs a profile logged in on it beforehand.
README, errors table, examples and the agent-facing cli-skill all told readers to export PLIVO_AUTH_ID/PLIVO_AUTH_TOKEN. SKILL.md went further and instructed agents to authenticate that way in CI, which is now a dead end, so its Headless section says to stop and ask a human instead. COMMANDS.md regenerated via make docs.
Merged
3 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
config.Resolve()readPLIVO_AUTH_ID/PLIVO_AUTH_TOKENand ranked them above the active profile. That is the one path by which a raw, long-livedauth_tokenenters the CLI — pasted into a shell profile, or held as a CI secret — which is exactly the material the PKCE handshake exists to avoid minting. With it present, the hardened flow was opt-in.This removes it. Credentials now come only from a profile written by
plivo login.Resolution order:
--profile→ active profile.Behaviour change
BREAKING: headless/CI callers that exported those vars no longer authenticate. There is no device-code flow, so such a host needs a profile logged in on it beforehand.
cli-skill/SKILL.mdpreviously instructed agents to authenticate this way; its Headless section now tells them to stop and ask a human rather than attempt it.Notes for review
scripts/smoke.shdepended on this. It exported placeholder creds so the ~21--dry-runURL assertions could resolve a credential, and runs in CI on Linux/macOS/Windows. It now writes a throwaway profile into a tempHOME.USERPROFILEis set alongsideHOMEbecause Go'sos.UserHomeDir()reads that one on the Windowssmoke-osleg. No product code was bent to accommodate the test.credentialHint()loses its unreachable"env"case. The surviving profile branch also changesplivo login --profile X→--name X:--profileselects a profile, it does not name one at login, so the old hint pointed at a no-op.TestResolve_*Env*cases were the removed feature's own unit tests and are deleted.TestResolve_credEnvVarsAreIgnoredreplaces them as a regression guard.setFakeCredsused env vars as its only way to supply credentials, so it now writes a profile;setEmptyHomewas split out for the two tests that genuinely want an empty config.agents-skill/SKILL.md:298left alone on purpose — that Python snippet callsapi.plivo.comdirectly with Basic auth and never goes through the CLI's resolution.RELEASING.mdstep 2 that section is written in thechore: cut vX.Y.ZPR.Verification
make fmt vet test test-tap test-release-notes— greenmake docs && git diff --exit-code docs/COMMANDS.md— clean (regenerated, committed)./scripts/smoke.sh ./plivo— passes locally on Darwin/arm64HOME→AUTH_MISSING; real profile →plivo auth whoamireturns the live account