feat(grant): positional provider:handle grantees + repo clone URL (COR-699) · Entire

feat(grant): positional provider:handle grantees + repo clone URL (COR-699)

b935e81→main· toothbrush·2w ago·7 files·+309 added/-228 removed

Address grantees as github:alice instead of --provider/--provider-user-id

flag soup: grant {org,project,repo} add/remove now take a positional <target> <grantee>, resolving the handle to its provider user id via the control plane (new resolveGranteeProvider). remove also accepts an account ULID for the typed-id revoke route. Show the entire:// clone URL in repo get.

Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com

Sessions

3018b0b38bf3

View transcript

Changes

7

import (
    "context"
    "errors"
    "fmt"

"github.com/spf13/cobra"
)

// validateGrantGranteeType rejects grantee kinds the control plane no longer
// accepts when granting. A grant resolves to an account (from the provider
// identity), so "account" is the only valid kind ("" means the default,
// account). org/team granting was dropped server-side (COR-561) and the
// generated client enum is account-only, so catch it here with a clear message
// instead of an opaque enum-encoding error.
func validateGrantGranteeType(granteeType string) error {
    switch granteeType {
    case "", "account":
        return nil
    default:
        return fmt.Errorf("invalid --grantee-type %q: only \"account\" is supported", granteeType)
    }
}

// newGrantCmd is the hidden `entire grant` command group: manage access
// grants and org membership on the Entire control plane. Org, project, and
// repo each support add / list / remove. Surfaced via `entire labs`.
//
// Grantees are addressed by their identity provider + provider user id
// (e.g. --provider github --provider-user-id 12345), matching the control
// plane's grant model. Handle-based addressing is a follow-up.
// Grantees are addressed by a provider-qualified handle (e.g. github:alice),
// which the CLI resolves to the provider account behind the scenes. `remove`
// also accepts an account ULID to revoke a grant by id. Targets (org, project,
// repo) are addressed by name or ULID.
func newGrantCmd() *cobra.Command {
    cmd := &cobra.Command{
        Use:    "grant",
    }
    return cmd
}

// ... function implementations continued...

Additional Details