cli: make auth status/logout context-only (COR-393) · Entire

cli: make auth status/logout context-only (COR-393)

b683975→main

resolveStatusTarget loses its legacy-keyring fallback and probes only the active context. With no login at all, auth status prints an informational "Not logged in. Run 'entire login'." (exit 0) and logout no-ops — neither ever targeted a default host with a stale identity. logout's revoke now takes the already-resolved bearer instead of re-reading a legacy store slot, and the legacy-slot cleanup in --all-contexts goes with it.

Co-Authored-By: Claude Fable 5 noreply@anthropic.com

Sessions

987ef1ca3188View transcript

Changes

4

32 unmodified lines

lastUsedJustNow = "just now"

// requireSecureBaseURL enforces TLS unless insecureHTTPAuth is set. Every
// command that sends a bearer token over the network (login, logout,
// auth status) must call this so credentials don't leak over plaintext HTTP
// without explicit opt-in.
// ... (code omitted for brevity)

// The token is resolved through resolveLogin, which transparently re-mints
// an expired login JWT from the stored refresh token. This is the point of the refresh: an
// expired-but-refreshable session must report "logged in", not "re-login" — the same false negative
// auth.ResolveControlPlaneTarget already avoids for org/repo/project/grant. `logout` benefits too:

// ... (code omitted for brevity)

// TestResolveStatusTarget_FallsBackToStoredWhenRefreshFails pins the safety net:
// when refresh fails (revoked family, network, opaque token) status drops to the
// stored token and lets the /me probe arbitrate — rather than skipping to the
// legacy entry or losing the active context.

// ... (code omitted for brevity)

// makeContextJWT builds a JWT-shaped token (non-"none" alg) carrying the
// given claims, which is all RecordLoginContext needs.

... (code omitted for brevity)


```go
  // tokenStore abstracts keyring access so commands that read or delete the
// stored bearer token can be unit-tested without hitting the real OS keyring.
// Used by logout and the auth subcommands.
// ... (code omitted for brevity)

func TestRunLogout_RevokesServerSideThenDeletesLocally(t *testing.T) {

// ... (code omitted for brevity)
}

// TestRunLogout_RevokeFailureWarnsButSucceeds(t *testing.T) can be similarly abstracted.