Repository navigation
feat(cli): sign in with an app password for unattended sync - #279
Conversation
There was a problem hiding this comment.
The auth plumbing is correct. Caller on the base branch accepts Basic app-password credentials, SessionCaller returns 403 for them, and the three new tests match that behaviour. The Authorize swap covers every request site.
One blocking finding: the minted app password response is redefined in the client instead of being shared through stashden_core. One nit on an export that has no use yet.
e568ca0 to
dcc59ac
Compare
There was a problem hiding this comment.
0626f4d drops Credential from the re-exports, which settles the nit. The blocking thread on crates/client/src/remote.rs is still open: MintedAppPassword is still defined in the client, not shared from stashden_core, and its derived Debug still prints secret. Nothing new in this push.
0626f4d to
f769eb6
Compare
There was a problem hiding this comment.
78aa97e moves the minted app password type into stashden_core::app_password, matching how share::Minted is set up (postgres-gated FromRow, Debug with the secret redacted, wire-shape test). The blocking thread is resolved and no findings remain.
Signed-off-by: BryanFRD <bryanferrando59@gmail.com>
Co-authored-by: ferrfleet[bot] <307549260+ferrfleet[bot]@users.noreply.github.com> Signed-off-by: BryanFRD <bryanferrando59@gmail.com>
…d the client Signed-off-by: BryanFRD <bryanferrando59@gmail.com>
78aa97e to
aae9618
Compare
Second layer of #261: the client and the CLI sign in with an app password.
Remote::with_app_passwordauthenticates every request with Basic auth instead of a Bearer token.mint_app_passwordandrevoke_app_passwordwrap the existing routes.STASHDEN_EMAILandSTASHDEN_APP_PASSWORD(or--email/--app-password) and prefers them overSTASHDEN_TOKEN.stashden login <email> --create-app-password <name>mints one and prints the two variables to keep, for async --watchthat runs unattended.End-to-end tests in
api/tests/client.rsrun the client against the real API: an app-password client lists and uploads, cannot mint another one, and is signed out once revoked.Refs #261