cli/auth: surface the secret caveat in `auth token` help · Entire
cli/auth: surface the secret caveat in auth token help
58f798b·
georg·2w ago·1 file·+18 added/-13 removed
The "treat the output as a secret" warning only lived in the Go doc comment, which --help never shows. Now that the command is discoverable, put the caveat in Short (so it appears in the entire auth --help subcommand list) and add a Long + curl Example that carry it in full. Trim the doc comment to point at them instead of duplicating the prose.
Addresses Copilot review comment on #1619.
Sessions
56c477a9ab1fView transcript
Changes
1
cmd/entire/cli
Mauth.go+18/-13
125 unmodified lines
// --- token ------------------------------------------------------------------
// newAuthTokenCmd prints the active control-plane bearer to stdout so scripts
// (and ad-hoc curl) can authenticate against the core API without re-deriving
// the keychain slot — e.g.
//
// curl -H "Authorization: Bearer $(entire auth token)" "$CORE/api/v1/clusters"
//
// It emits a live credential, so treat the output as a secret. It resolves the
// same bearer the API client would — ENTIRE_TOKEN verbatim when set, otherwise
// the active context's login JWT, refreshed if it's near expiry — and prints
// nothing but the token (errors and the not-logged-in hint go to stderr) so
// command substitution stays clean.
// newAuthTokenCmd prints the active control-plane bearer to stdout for
// scripting. The user-facing Long and Example carry the detail and the
// "treat the output as a secret" caveat; the token resolves the same way the
// API client's does (ENTIRE_TOKEN verbatim when set, otherwise the active
// context's login JWT, refreshed if it's near expiry), and only the token is
// printed — errors and the not-logged-in hint go to stderr so command
// substitution stays clean.
func newAuthTokenCmd() *cobra.Command {
var insecureHTTPAuth bool
cmd := &cobra.Command{
Use: "token",
Short: "Print the active control-plane bearer token (for scripting)",
Args: cobra.NoArgs,
Short: "Print the active control-plane bearer token — a live credential, treat as a secret",
Long: "Print the active control-plane bearer token to stdout so scripts and\n" +
"ad-hoc curl can authenticate against the core API without re-deriving the\n" +
"keychain slot.\n\n" +
"The output is a live credential — treat it as a secret. It is the same\n" +
"bearer the API client uses: ENTIRE_TOKEN verbatim when set, otherwise the\n" +
"active context's login JWT (refreshed if it's near expiry). Only the token\n" +
"is printed to stdout; errors and the not-logged-in hint go to stderr so\n" +
"command substitution stays clean.",
Example: " curl -H \"Authorization: Bearer $(entire auth token)\" \"$CORE/api/v1/clusters\"",
Args: cobra.NoArgs,
RunE: func(cmd *cobra.Command, _ []string) error {
// Refresh may exchange/refresh over the network; honor the\n // plain-HTTP opt-in before resolving so local dev cores work.