Conversation
…ng a new one writeCLIHandoffPage minted a key named "CLI login" on every OAuth callback with no lookup of an existing key, no revoke, and no device identity, so every `e2a login` (or config wipe) added another indistinguishable, never-expiring key. The CLI now sends the machine's hostname as device_name on the login URL; the server sanitizes it to printable ASCII (<=64 chars) and, when present, revokes the caller's prior key of the same device-scoped name before minting its replacement. Without a device name (older CLI binaries, or a login door that does not plumb one) the server keeps minting a fresh "CLI login" key, so it never revokes a different device's still-live key by a shared, unscoped name. Fixes tokencanopy#44
…accumulation # Conflicts: # cli/CHANGELOG.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
writeCLIHandoffPageminted an API key named"CLI login"on every successfulCLI OAuth callback, with no lookup of an existing key, no revoke, and no
device identity, so every
e2a login(or a config wipe) left anotherindistinguishable, never-expiring key behind. A key from a lost or wiped
machine had no name that told it apart from a current one, so it stayed live
until someone found and revoked it by hand.
The CLI now appends the machine's hostname as
device_nameon the browserlogin URL (falling back silently if the hostname lookup throws, so a login
never fails over it). The server sanitizes that value to printable ASCII,
capped at 64 characters, and when it is present, names the new key
"CLI login on <device>"and revokes any live key with that exact namebefore minting the new one, so re-authenticating from the same machine
replaces its own key instead of adding another. Without a device name (older
CLI binaries, or a login door that never plumbs one in) the server keeps the
old behavior of minting a fresh
"CLI login"key every time, since revokingby that shared, unscoped name could otherwise take out a different device's
still-live key.
No migration:
revoked_atand its index already exist onapi_keys(
migrations/001_init.sql).Operational risk
No schema change, no change to the request/response shape of anything under
/v1.device_nameis an optional query parameter the login endpoint didnot previously read; older CLI versions that omit it keep today's behavior
exactly. The dashboard's key list will start showing
"CLI login on <host>"names for anyone re-authenticating with the new CLI, alongside any older
plain
"CLI login"rows from before the upgrade.Test plan
TestHandleCallback_CLILogin_SameDeviceReplacesPriorKeyis the regressiontest: two logins from the same device name leave exactly one live
"CLI login on <device>"key, and it is the second mint. It does notcompile against main (no
DeviceNamefield there yet) and passes here,alongside
TestHandleCallback_CLILogin_NoDeviceName_PreservesLegacyAccumulation,which pins that two logins with no device name still leave two distinct
"CLI login"rows.go test ./internal/auth/... ./internal/identity/...andnpx vitest run src/__tests__/login.test.ts(cli/) both green.go vet ./internal/auth/... ./internal/identity/...andmake fmt-checkclean.
Go coverage gate's full per-package floors.
Fixes #44