Repository navigation
feat: improve cli scripting workflows - #12
Merged
Merged
Conversation
leiysky
force-pushed
the
dev/json-output-and-cli-safety
branch
from
September 23, 2026 18:29
72a25b5 to
5f5eee5
Compare
tisonkun
reviewed
Sep 24, 2026
|
|
||
| * `scope login`, `logout`, `workspace use`, `api-key revoke`, `open`, and `version` now support `--format json` for machine-readable action results. | ||
| * `scope query`, `workspace show`, and `api-key` commands accept `--workspace` to target an available workspace for one command without changing the saved selection. | ||
| * `scope --no-prompt` and `SCOPEDB_PROMPT_DISABLED` disable interactive questions while still accepting piped login codes and explicit `api-key revoke --yes` confirmation. |
Contributor
There was a problem hiding this comment.
I have two comments on this change:
- Where do we need this option now?
scopewithout arguments is for interactive use; certain final actions (e.g.,query) could be run without prompts. - Even if we want a quiet mode, I'd prefer to call it
--no-interactiveandSCOPEDB_NO_INTERACTIVE=true.
tisonkun
reviewed
Sep 24, 2026
| scope status --format json | ||
| scope workspace use <id-or-name> --format json | ||
| scope api-key revoke <name> --yes --format json | ||
| scope open --print --format json |
Contributor
There was a problem hiding this comment.
Follow-up ideas:
I'd prefer to name the command as scope console and use --open to open the browser while default to print the URL.
tisonkun
reviewed
Sep 24, 2026
| } | ||
| command.Flags().StringVar(&email, "email", "", "email address") | ||
| command.Flags().StringVar(&code, "code", "", "verification code (for non-interactive input)") | ||
| command.Flags().StringVar(&code, "code", "", "verification code (visible in process arguments; prefer stdin)") |
Contributor
There was a problem hiding this comment.
Follow-up idea:
We may later learn from AWS CLI's login experience to avoid this composed email login scaffolding.
tisonkun
reviewed
Sep 24, 2026
tisonkun
left a comment
Contributor
There was a problem hiding this comment.
Rest LGTM. Follow-up ideas need not to be implemented in this PR.
tisonkun
self-requested a review
October 4, 2026 05:22
Contributor
|
I'll handle this and merge it today. |
Remove --workspace from query, workspace show, and API key commands. Use the workspace bound to the saved session and remove the override helpers, fixtures, and unreleased documentation. The control plane rejects workspace requests when the session is unbound or its workspace differs from the route. Changing State.WorkspaceID does not change the token's authorization. SelectWorkspace issues a replacement session and revokes the previous one, so calling it cannot provide an isolated one-command override either. These restrictions predate the workspace override feature. TestWorkspaceOverrideUsesTargetWithoutChangingSelection passed because its mock reported an unbound session but accepted that same token for every ws-2 endpoint, while explicitly asserting that no selection occurred. It checked routing and local persistence without modeling authorization. The original test passes; adding the server's unbound-session rejection in a temporary Go overlay makes its first query fail with "session is not bound to a workspace". Support for independently authenticated local profiles belongs in a separate change. Selecting a profile should choose its own credentials; copying and rotating another profile's session would invalidate that profile instead of preserving independent contexts. Validation: mise run check; mise run test:race.
Remove --no-interactive, SCOPEDB_NO_INTERACTIVE, and their prompt-control state, parsing, tests, and unreleased documentation. Keep list-limit coverage in a dedicated test file. Use the existing terminal checks and explicit inputs: login accepts a piped verification code and requires --email without a terminal, while API key revocation requires --yes without a terminal. Interactive login and revocation confirmation keep their existing behavior. Validation: mise run check, mise run build, and mise run test:race. Binary smoke checks confirm that piped confirmation cannot authorize revocation, non-terminal login requires an email, and terminal cancellation returns a JSON result without making a service request.
Compare complete action JSON with small inline expectations instead of round-tripping through implementation DTOs and asserting individual fields. Keep session rotation, idempotent actions, browser invocation, and cancelled revocation observable at the command boundary. Consolidate login persistence failures around one HTTP fixture and one write-interruption adapter. Cover valid credential restoration, cleanup of a first login, replacement of an invalid profile, preservation of an unreadable credential document, and revocation of an unsaved session. Remove duplicate variations of the same recovery boundary and test-side reimplementation of credential profile hashing. Move the file-permission regression into the existing query tests and keep one-time key exclusion alongside list rendering. Product behavior is unchanged; the test suite loses 141 lines. Validation: mise run check; mise run test:race.
tisonkun
approved these changes
Oct 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary