[CLI] wallet show is not machine-parseable, same as wallet list - #727
Conversation
`wallet show <name>` printed a readable summary through log() and returned undefined, so `nansen wallet show main | jq .` failed and --pretty, --table and --fields did nothing. It now returns showWallet(), following the rule #584 set for `wallet list`: same envelope in a terminal and a pipe, nothing on stderr, no isTTY switch. The redacted default of `wallet export` had the same problem. It now returns the addresses with `redacted: true` and no key fields. The --reveal and --file paths are unchanged. Adds `returns` for both commands to schema.json. Tests drive runCLI with isTTY true and false. Closes API-686. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
pr-reviewer Summary for #43ae539✅ No issues found The code review completed successfully with no findings. Review effort: 2/5 (Simple) SummaryThis PR extends the machine-parseable JSON envelope pattern (established in PR #584 for Production changes reviewed:
Tests reviewed:
No bugs, logic errors, security issues, or CLAUDE.md/AGENTS.md violations found. Token usage: 11,074 input, 4,276 output, 796,809 cache read, 51,538 cache write | Usage Guide New pushes are reviewed automatically with a 10-minute cooldown between reviews. To request a review at any time, comment |
There was a problem hiding this comment.
Auto-approved
This PR was automatically approved because:
- Claude recommends approval
- Claude assessed this as a moderate effort change
- The effort level is within the auto-approval threshold of 2
- No high or critical issues were detected
If you have any concerns, please request a manual review.
Codier
left a comment
There was a problem hiding this comment.
Reviewer A (Factory droid deepseek-v4-pro, max effort) reviewed head 43ae539 and found nothing to fix.
What it checked:
npm test: 109 files, 4503 passed, 9 skipped. Lint andmcp:checkpass.- It copied the base
src/wallet.jsover the fix: exactly the 6 new tests failed. It also injected a decrypted EVM key into the redacted export result: both redacted-export tests failed. The checkout was clean afterwards. - Real CLI with a throwaway HOME:
wallet showin default,--pretty,--table,--format csv,--streamand--fieldsmodes gives a valid envelope. Under a pseudo-terminal the JSON was byte-identical, so there is no isTTY branch. - It grepped the real EVM and Solana keys against stdout and stderr of redacted
wallet exportin every output mode, including--fields privateKey: no hits. Redacted export succeeds with a wrong password and with the credential store deleted, so it never decrypts. - Privy:
wallet showreturnsprivyWalletIds;wallet exportstill rejects Privy wallets withEXPORT_FAILED. - BI: with fetch intercepted,
wallet show, redactedwallet exportandwallet default(still on the no-output branch) sendcli_command_succeededwith the same property keys,from_cache: falseand no result data. A missing wallet sendscli_command_failedwithSHOW_FAILED. The PR's BI claim holds. - Nothing in
src/,scripts/orevals/parses show/export stdout; internal callers importshowWallet/exportWalletdirectly.
Judgment calls it accepted: dropping the "how to export keys" hint follows the no-stderr, no-isTTY rule, and --help plus the schema description still document both flags. returns on wallet export follows the cache stats precedent. Omitting the key fields, rather than null or [REDACTED], is unambiguous.
Not run: npm run test:privy, which needs real Privy credentials. The Privy path was covered with a synthetic wallet file.
Reviewer B reviews next.
Codier
left a comment
There was a problem hiding this comment.
Reviewer B (Factory droid gpt-5.6-sol, high effort) independently reviewed head 43ae539 and found nothing to fix. Round A made no changes, so this is the same head.
What it checked:
- Focused tests: 2 files, 97 passed. Full
npm test: 109 files, 4503 passed, 9 skipped. Lint,mcp:checkandgit diff --checkpass. - With the base handlers restored, exactly the 6 new tests failed. A mutation that decrypts in the redacted path made both redacted-export guard tests fail.
- Real CLI: default JSON,
--pretty,--table,--format csv,--stream,--fields, missing-wallet errors, and legacy or partial wallet files all behaved. No synthetic key material appeared in any output. - BI: base and head telemetry match. Same
cli_command_succeededevent and paths,from_cache: false, no result data. - No internal caller relies on the old text or the
undefinedreturn; directshowWallet/exportWalletcallers are unchanged.
The checkout stayed clean.
Codier
left a comment
There was a problem hiding this comment.
Approving head 43ae539 on the evidence from two independent reviewers. Both returned clean with no findings, and no code changed between the rounds.
Across both rounds:
- The full suite passes.
- The new tests fail against the old handlers.
wallet showand redactedwallet exportgive one JSON envelope on stdout in every output mode. It is the same in a pipe and a pseudo-terminal, with nothing on stderr.- No private key material appears in any mode, and redacted export never decrypts.
- BI telemetry is unchanged.
All CI checks on this head pass. The writer was Claude Opus 5.5; this approval rests on the external reviewers' reports, not the writer's own checks.
All three swap e2e groups gated on `wallet list` printing an `EVM:` / `Solana:` summary, but that command reports data and so prints the standard JSON envelope on stdout in a terminal and a pipe alike (#584, extended to `wallet show` and redacted `wallet export` in #727). The preconditions could therefore never pass, and because each group is sequential, the whole file was unrunnable. Parse the envelope through one `walletAddresses()` helper instead of grepping prose, and take the Solana address from the parsed wallet rather than a base58 regex over human output. Pre-existing on main; unrelated to the execution route, but it blocks any e2e run of it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Closes API-686. Follow-up to #584.
Problem
nansen wallet show <name>printed a readable summary throughlog()and returnedundefined, sonansen wallet show main | jq .failed with a parse error and--pretty,--tableand--fieldsdid nothing. The redacted default ofnansen wallet export <name>had the same problem.Change
wallet showreturnsshowWallet(name). Stdout carries{"success":true,"data":{name, provider, evm, solana, createdAt, isDefault}}, plusprivyWalletIdsfor Privy wallets. Same output in a terminal and a pipe, nothing on stderr, noisTTYswitch, per the rule fix: wallet list writes only JSON to stdout (#154) #584 settled on.wallet export <name>without--revealor--filereturns{name, redacted: true, evm: {address}, solana: {address}}. The key fields are left out instead of holding a[REDACTED]placeholder, so nothing key-shaped reaches a caller. It still never decrypts or asks for a password, and still rejects non-local wallets.--revealand--fileare unchanged.--file,--reveal). That hint is gone from the output; thewallet exportdescription inschema.json(shown by--help) says it.schema.json:returnsforwallet showandwallet export; the export description notes the JSON default.AGENTS.md: the operational-commands exception now listswallet showand redactedwallet export.Checks
npm test: 109 files, 4503 passed, 9 skipped.npm run lintandnpm run mcp:checkpass.runCLIwithisTTYfalse and true forwallet showand redactedwallet export, and require one parseable envelope with nothing on stderr. Also covered: PrivyprivyWalletIds,--fieldson show, and no key material or 64-hex blob in the export output.src/wallet.jsrestored toorigin/main, all 6 new tests fail; with the fix, they pass.HOME:wallet show main | jqandwallet export main | jqparse with empty stderr,wallet show main --tablerenders a table,wallet show nopereturns{"success":false,...,"code":"SHOW_FAILED"}with exit 1, and--revealstill prints text.BI
No event affected. Both commands still send the same
cli_command_succeeded/cli_command_failedevent with the same command path. Returning data sends the success event through the data branch ofrunCLI, which passesfrom_cacheexplicitly; theundefinedbranch left it at itsfalsedefault, and nothing on a wallet command reads from the cache, so the properties are identical. The event carries no result data.AI execution metadata
claude-opus-5-5deepseek-v4-pro,gpt-5.6-sol) is reported separately in the review posts.🤖 Generated with Claude Code