auth: show active sessions in `auth status`; logout targets same core · Entire
auth: show active sessions in auth status; logout targets same core
f9b8c3e·
toothbrush·1mo ago·3 files·+196 added/-44 removed
Bring back the sessions table now that it correctly lists entire-core login sessions (not entire.io PATs), so the effect of logout / logout --all is visible:
auth statuslists the active sessions (NAME / CREATED / LAST USED / EXPIRES) on the active context's core, after the profile/context lines, with a hint tying the table tologoutandlogout --all. Best-effort: a listing failure is a soft note (liveness already confirmed via /me).logoutnow revokes against the active context's core too (shared resolveStatusTarget), so it acts on exactly the sessions status shows — not a static AuthBaseURL. Fixes the same multi-core mismatch for logout.- newSessionsClient takes an explicit coreURL.
Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com
Sessions
8159eed97febView transcript
Changes
3
cmd/entire/cli
Mauth.go+106/-18
- Mauth_test.go+65/-7
- Mlogout.go+25/-19
5 unmodified lines
6
7
8
9
10
11
12
13
14
14 unmodified lines
29
30
31
32
33
34
35
31 unmodified lines
67
68
69
67
68
69
70
71
72
73
74
75
70
71
72
73
74
75
76
77
78
96 unmodified lines
175
176
177
178
178
179
180
181
14 unmodified lines
196
197
198
199
200
201
202
203
204
205
206
207
203
204
205
208
209
210
211
212
213
214
51 unmodified lines
266
267
268
263
264
265
266
267
269
270
271
272
273
274
275
276
277
278
279
280
281
17 unmodified lines
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
98 unmodified lines
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
5 unmodified lines
"fmt"
"io"
"net/http"
"sort"
"strings"
"time"
"charm.land/lipgloss/v2"
"github.com/entireio/cli/cmd/entire/cli/api"
14 unmodified lines
// formatRelativeDuration in status.go.
const (
placeholderDash = "-"
lastUsedNever = "never"
lastUsedJustNow = "just now"
)
31 unmodified lines
// newSessionsClient builds an api.Client for entire-core's login-session
// endpoints (coreSessionsPath). It targets the auth host (api.AuthBaseURL()),
// since that's where the session/refresh-token families live; the supplied
// bearer must be the session-scoped login JWT, obtained via
// resolveAuthHostToken (a same-host resolution that returns the login token
// unchanged, preserving its entire:session scope — entire-core's session
// routes require it).
func newSessionsClient(token string) *api.Client {
return api.NewClientWithBaseURL(token, api.AuthBaseURL()).
WithSessionsPath(coreSessionsPath)
}
// endpoints (coreSessionsPath) on coreURL, authenticated with the
// session-scoped login JWT. coreURL is the active context's CoreURL (or the
// configured auth host when no context is active) — session management always
// targets a login server, never the data host.
func newSessionsClient(coreURL, token string) *api.Client {
return api.NewClientWithBaseURL(token, coreURL).WithSessionsPath(coreSessionsPath)
}
// resolveAuthHostToken returns a bearer scoped for the auth host (entire-core).
96 unmodified lines
return fmt.Errorf("context core URL check: %w", err)
}
}
return runAuthStatus(cmd.Context(), cmd.OutOrStdout(), defaultFetchProfile, target)
return runAuthStatus(cmd.Context(), cmd.OutOrStdout(), defaultFetchProfile, defaultListSessions, target)
},
}
addInsecureHTTPAuthFlag(cmd, &insecureHTTPAuth)
14 unmodified lines
// with token. Injected so status stays unit-testable without a live core.
type profileFetcher func(ctx context.Context, coreURL, token string) (*authProfile, error)
// sessionLister lists the active login sessions on coreURL (the user's
// refresh-token families). Injected for testability; production wires
// defaultListSessions.
type sessionLister func(ctx context.Context, coreURL, token string) ([]api.Session, error)
// contextsProvider returns the stored login contexts and the active context
// name. Injected for testability; production wires auth.Contexts.
type contextsProvider func() ([]*contexts.Context, string, error)
// statusTarget is the resolved core `entire auth status` should query: the
// active context's CoreURL + its session token, or (no active context) the
// configured AuthBaseURL + legacy keyring entry.
// statusTarget is the resolved core to act against: the active context's
// CoreURL + its session token, or (no active context) the configured
// AuthBaseURL + legacy keyring entry. Shared by `auth status` (profile +
// session list) and `logout` (revocation) so both hit the same login server.
type statusTarget struct {
coreURL string
token string
51 unmodified lines
return p, nil
}
// runAuthStatus reports auth state without listing server-side sessions: GET
// /me on the target core validates the token and supplies the profile header,
// and the active login context is shown locally. (Session listing/revocation
// lives on entire-core and is reached only by logout — see newSessionsClient.)
func runAuthStatus(ctx context.Context, w io.Writer, fetchProfile profileFetcher, t statusTarget) error {
// defaultListSessions lists the user's active login sessions on coreURL.
func defaultListSessions(ctx context.Context, coreURL, token string) ([]api.Session, error) {
return newSessionsClient(coreURL, token).ListSessions(ctx) //nolint:wrapcheck // ListSessions already wraps with action context
}
// runAuthStatus reports auth state against the target core: GET /me validates
// the token and supplies the profile header, the active login context is shown
// locally, and the active sessions (refresh-token families) on that core are
// listed so the effect of `logout` / `logout --all` is visible.
func runAuthStatus(ctx context.Context, w io.Writer, fetchProfile profileFetcher, listSessions sessionLister, t statusTarget) error {
if t.token == "" {
fmt.Fprintf(w, "Not logged in to %s\n", t.coreURL)
fmt.Fprintln(w, "Run 'entire login' to authenticate.")
}
fmt.Fprintf(w, " %-9s %s\n", "Token:", "stored in OS keychain")
// Active sessions on this core. The token is already known good, so a
// listing failure is non-fatal — note it and carry on.
sessions, serr := listSessions(ctx, t.coreURL, t.token)
switch {
case serr != nil:
fmt.Fprintf(w, "\n(could not list active sessions: %v)\n", serr)
case len(sessions) > 0:
sortSessionsByRecency(sessions)
fmt.Fprintf(w, "\nActive sessions (%d):\n", len(sessions))
renderSessionsTable(w, newAuthTableStyles(w), sessions)
fmt.Fprintln(w, "\nRun 'entire logout' to end this session, or 'entire logout --all' to end all of them.")
}
if t.totalContexts > 1 {
fmt.Fprintln(w)
fmt.Fprintf(w, "%d login contexts saved; run 'entire auth contexts' to list or 'entire auth use <name>' to switch.\n", t.totalContexts)
98 unmodified lines
}
// renderSessionsTable prints the active login sessions as an aligned table.
// No id column: there's no per-session CLI action (revoke-by-id is gone), so
// NAME/CREATED/LAST USED/EXPIRES is what's useful.
func renderSessionsTable(w io.Writer, sty authTableStyles, sessions []api.Session) {
header := []string{
sty.render(sty.header, "NAME"),
sty.render(sty.header, "CREATED"),
sty.render(sty.header, "LAST USED"),
sty.render(sty.header, "EXPIRES"),
}
rows := make([][]string, 0, len(sessions))
for _, s := range sessions {
rows = append(rows, []string{
sty.render(sty.name, fallback(s.Name, placeholderDash)),
sty.render(sty.value, formatAuthDate(s.CreatedAt)),
sty.render(sty.value, formatLastUsed(s.LastUsedAt)),
sty.render(sty.value, formatAuthDate(s.ExpiresAt)),
})
}
renderAlignedTable(w, header, rows)
}
// sortSessionsByRecency orders sessions most-recently-used first, then most
// recently created, then by id — a fully specified order independent of the
// server's response ordering.
func sortSessionsByRecency(sessions []api.Session) {
sort.Slice(sessions, func(i, j int) bool {
li, lj := lastUsedSortKey(sessions[i]), lastUsedSortKey(sessions[j])
if li != lj {
return li > lj
}
if sessions[i].CreatedAt != sessions[j].CreatedAt {
return sessions[i].CreatedAt > sessions[j].CreatedAt
}
return sessions[i].ID < sessions[j].ID
})
}
func lastUsedSortKey(s api.Session) string {
if s.LastUsedAt == nil {
return ""
}
return *s.LastUsedAt
}
// formatAuthDate renders an RFC3339 timestamp as YYYY-MM-DD in local time,
// falling back to a dash (empty) or the raw value (unparseable).
func formatAuthDate(s string) string {
if s == "" {
return placeholderDash
}
if ts, err := time.Parse(time.RFC3339, s); err == nil {
return ts.Local().Format("2006-01-02")
}
return s
}
func formatLastUsed(s *string) string {
if s == nil || *s == "" {
return lastUsedNever
}
return formatAuthDate(*s)
}