Skip to content

feat: improve cli scripting workflows - #12

Merged
tisonkun merged 9 commits into
mainfrom
dev/json-output-and-cli-safety
Oct 4, 2026
Merged

tisonkun merged 9 commits into
mainfrom
dev/json-output-and-cli-safety

Conversation

@leiysky

@leiysky leiysky commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Add JSON output to action commands while preserving existing human-readable defaults, and add list output limits.
  • Hide terminal verification codes and make login persistence recover from invalid credentials while restoring valid credentials when the final configuration write fails.
  • Restrict query output file permissions and exclude one-time key material from API key lists.

@leiysky
leiysky force-pushed the dev/json-output-and-cli-safety branch from 72a25b5 to 5f5eee5 Compare September 23, 2026 18:29
@leiysky leiysky changed the title feat: add json output to action commands feat: improve cli scripting workflows Sep 23, 2026
@leiysky
leiysky requested a review from tisonkun September 24, 2026 08:32
Comment thread CHANGELOG.md Outdated

* `scope login`, `logout`, `workspace use`, `api-key revoke`, `open`, and `version` now support `--format json` for machine-readable action results.
* `scope query`, `workspace show`, and `api-key` commands accept `--workspace` to target an available workspace for one command without changing the saved selection.
* `scope --no-prompt` and `SCOPEDB_PROMPT_DISABLED` disable interactive questions while still accepting piped login codes and explicit `api-key revoke --yes` confirmation.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have two comments on this change:

  1. Where do we need this option now? scope without arguments is for interactive use; certain final actions (e.g., query) could be run without prompts.
  2. Even if we want a quiet mode, I'd prefer to call it --no-interactive and SCOPEDB_NO_INTERACTIVE=true.

Comment thread README.md
scope status --format json
scope workspace use <id-or-name> --format json
scope api-key revoke <name> --yes --format json
scope open --print --format json

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Follow-up ideas:

I'd prefer to name the command as scope console and use --open to open the browser while default to print the URL.

Comment thread internal/command/login.go
}
command.Flags().StringVar(&email, "email", "", "email address")
command.Flags().StringVar(&code, "code", "", "verification code (for non-interactive input)")
command.Flags().StringVar(&code, "code", "", "verification code (visible in process arguments; prefer stdin)")

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Follow-up idea:

We may later learn from AWS CLI's login experience to avoid this composed email login scaffolding.

@tisonkun tisonkun left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Rest LGTM. Follow-up ideas need not to be implemented in this PR.

@tisonkun
tisonkun self-requested a review October 4, 2026 05:22
@tisonkun

tisonkun commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

I'll handle this and merge it today.

Remove --workspace from query, workspace show, and API key commands. Use the
workspace bound to the saved session and remove the override helpers,
fixtures, and unreleased documentation.

The control plane rejects workspace requests when the session is unbound
or its workspace differs from the route. Changing State.WorkspaceID does
not change the token's authorization. SelectWorkspace issues a replacement
session and revokes the previous one, so calling it cannot provide an
isolated one-command override either. These restrictions predate the
workspace override feature.

TestWorkspaceOverrideUsesTargetWithoutChangingSelection passed because its
mock reported an unbound session but accepted that same token for every
ws-2 endpoint, while explicitly asserting that no selection occurred. It
checked routing and local persistence without modeling authorization.
The original test passes; adding the server's unbound-session rejection
in a temporary Go overlay makes its first query fail with "session is not
bound to a workspace".

Support for independently authenticated local profiles belongs in a
separate change. Selecting a profile should choose its own credentials;
copying and rotating another profile's session would invalidate that
profile instead of preserving independent contexts.

Validation: mise run check; mise run test:race.
Remove --no-interactive, SCOPEDB_NO_INTERACTIVE, and their prompt-control
state, parsing, tests, and unreleased documentation. Keep list-limit
coverage in a dedicated test file.

Use the existing terminal checks and explicit inputs: login accepts a
piped verification code and requires --email without a terminal, while
API key revocation requires --yes without a terminal. Interactive login
and revocation confirmation keep their existing behavior.

Validation: mise run check, mise run build, and mise run test:race.
Binary smoke checks confirm that piped confirmation cannot authorize
revocation, non-terminal login requires an email, and terminal
cancellation returns a JSON result without making a service request.
Compare complete action JSON with small inline expectations instead of
round-tripping through implementation DTOs and asserting individual fields.
Keep session rotation, idempotent actions, browser invocation, and cancelled
revocation observable at the command boundary.

Consolidate login persistence failures around one HTTP fixture and one
write-interruption adapter. Cover valid credential restoration, cleanup of
a first login, replacement of an invalid profile, preservation of an
unreadable credential document, and revocation of an unsaved session.
Remove duplicate variations of the same recovery boundary and test-side
reimplementation of credential profile hashing.

Move the file-permission regression into the existing query tests and keep
one-time key exclusion alongside list rendering. Product behavior is
unchanged; the test suite loses 141 lines.

Validation: mise run check; mise run test:race.
@tisonkun
tisonkun merged commit f08049a into main Oct 4, 2026
2 checks passed
@tisonkun
tisonkun deleted the dev/json-output-and-cli-safety branch October 4, 2026 06:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants