feat(auth): token admin, whoami, ping, config update (PR5) - #5
Merged
Merged
Conversation
arcli auth whoami and auth token {list,show,permissions,create,update,
rotate,revoke,delete} over /api/v1/auth/*; arcli ping over /health +
/verify; arcli config update for refreshing stored fields.
Secrets from create/rotate are the only plaintext tokens ever printed
and go to stdout alone. rotate --save rewrites every profile holding the
old token, printing the secret first and re-loading the config after the
rotate so concurrent edits are not clobbered. Revoke/delete refuse the
last enabled admin token without --force. Confirmation prompts now go to
stderr and are refused on non-TTY stdin without --yes.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
arcli auth whoamiandarcli auth token {list,show,permissions,create,update,rotate,revoke,delete}over Arc's/api/v1/auth/*routes. Tokens are addressed by numeric id or exact name.arcli ping:GET /health(no token sent) thenGET /api/v1/auth/verify; exit 1 on either failure,-o jsonalways emitted. A 404 on verify is reported as "auth disabled on server" (the route only exists when auth is on);/healthmust carry Arc'stime/uptimefields so a load balancer's own health page can't pass as Arc.arcli config update <name>for refreshing a stored token/endpoint/default-database/insecure flag.config create|updatenow validate the endpoint scheme+host and reject userinfo; profile names starting with(are rejected (Resolve's sentinels).createandrotateare the only commands that print a plaintext token, to stdout alone (T=$(arcli auth token create ...)works); reminders and ids go to stderr.rotate --saverewrites every profile that held the old token, prints the secret before touching the config, and re-loads the config after the rotate so a concurrentconfigedit during the prompt is not clobbered.--saveis refused up front for ad-hoc connections, when/verifycan't confirm the target is the token in use, or when the config dir isn't writable.--force; operating on the token in use prints a warning. Confirmation prompts now go to stderr (also fordb drop/config delete), answering anything but y/yes exits 1, and non-TTY stdin without--yesis refused.client.HTTPError(status + server message) replaces the string-only error fromdecodeWriteError;buildClientsplit intobuildClientFromso rotate can keep the loaded config.Test plan
gofmt -l .empty,go vet ./...,go test -race -count=1 ./...greentokens: null→[],new_tokenkey on rotate, nil-vs-emptypermissionson create, expires-in grammar; command flag validation with no network (--permission ,/""refused); httptest fake for create/rotate/delete/ping flows; concurrent-edit safety of--save; last-admin guardarc serve(HEAD e5c3f5e,ARC_AUTH_BOOTSTRAP_TOKEN): ping good/bad/unreachable/json, whoami, list, create (stdout capture + json id), show/permissions by name and id, update incl. empty-permission refusal, rotate (old secret dead, new works), self-rotate without--savethen repair viaconfig update,rotate --save -o json,--saverefused ad-hoc, revoke → 401 → rotate refused, delete by name/id/missing, last-admin guard and--force, non-admin token → 403, first-run error, sentinel name and userinfo endpoint refusedReview notes
Internal: adversarial review of the plan (3 design changes adopted before code), deep diff review (2 High fixed: empty
--permissionsilently sending[]; JSON-mode rotate printed the secret afterSave()), security review (checklist all PASS; 3 Medium fixed: lost-update race on--save, per-profile endpoint reporting, last-admin guard). Deferred:--token-stdinfollow-up.