Repository navigation
Conversation
`cloud auth login` now calls whoami:
- API key (flags or --interactive): verified before saving. A 401/403
exits 4 and saves nothing; any other failure saves with a warning so
offline setup still works. Prints key name, key ID and owning org.
- OAuth: after the device flow, prints the user and organizations; a
whoami failure only warns.
- --json prints {saved, identity, verification, warning?}.
`cloud auth status` checks the active credentials with a 5s timeout and
reports the identity as verified, rejected or unavailable, skipping the
call when nothing is configured. It always exits 0. JSON output is now
{sources: [...], identity, verification, warning?}.
Identity data stays out of telemetry. Help and README updated; the
typical flow no longer needs `org list` to confirm a login.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #1044. Stacked on #1045 (stack #1001).
What changes
cloud auth loginnow callswhoami:--api-key/--api-secretor--interactive): the key is verified before it is saved.--json: prints one object,{saved, identity, verification: "verified"|"unverified", warning?}.cloud auth statuschecks the active credentials with whoami, with a 5s timeout:Identity: rejected (…), orIdentity: unavailable (…).Help and README: the
cloudagent block's typical flow is nowauth login -> service list, and it points atauth login/whoamifor the identity. Thelogin,statusandwhoamiblocks are updated, and so are both README auth sections.auth statusauth status --jsonused to print a bare array of rows. It now prints{"sources": [...rows], "identity": <Whoami>|null, "verification": "verified"|"rejected"|"unavailable"|"skipped", "warning"?: "..."}. You can't add anidentityfield to an array, so the shape had to change.Implementation notes
CloudClientconstructors inclient.rs:for_api_key,for_oauth_tokensandnew_with_timeout.auth loginandauth statuspermission declarations now listwhoami_get, which is unscoped.Tests
cli_request_shape_test.rs:credentials.json), unreachable (saved with a warning).status: no credentials (no request), API-key identity, OAuth identity, 401 rejected, unreachable. All exit 0.oauth_login_report) is unit-tested with wiremock instead (success; 401/500 warn).--urland would now have reached production whoami, so they point at a mock now.cargo fmt, both clippy configurations, andcargo test -p clickhousectlall pass. The one exception islocal_postgres_readiness_test::failed_fresh_start_…, which fails withdocker_unavailablebecause Docker isn't running locally. That's unrelated to this change.Follow-ups (not in this PR)
auth login --jsonunder OAuth isn't pure JSON. That was already true before this change.infra-clickhouse/infra-postgresskills in ClickHouse/agent-skills need a matching update to their post-login check.🤖 Generated with Claude Code