Refine logout Command with --all-contexts Flag · Entire
We're working on https://github.com/entireio/cli/pull/1341 in this branch. Let's step through all the reviewer comments / nitpicks and consider what to do step by step.
What I did
2 live fixes applied to
cmd/entire/cli/logout.go:Dropped the double-
fmt.Errorfwraps inrevokeAllSessions—ListSessions/RevokeSessionalready wrap with their own prefix (incl. session id). No more"list sessions: list sessions: …".- Rewrote the stale
revokeCurrentFuncdoc comment — it claimed the impl "resolves its own data-API bearer"; the caller now resolvestarget.tokenand binds it into the closure.
- Rewrote the stale
Go lint clean, logout tests pass.
What I left alone
- Wrong-core revocation (Cursor medium-severity + Copilot's matching comment): already fixed in f9b8c3e; Bugbot's re-review confirmed no issues.
- "data-API bearer" comment on
revokeAllSessions(Copilot): already stale-corrected in a prior commit.
Note
- The
mise run lintshellcheck failure is pre-existing inmise-tasks/release(SC2312), untouched by this branch — not something to fix here.
Summary of Changes in Commits
Commit
9901fbf9e6— logout: stop double-wrapping session revoke errors- revokeAllSessions wrapped ListSessions/RevokeSession failures with their own prefixes, but (*api.Client) already wraps both (incl. the session id), producing "list sessions: list sessions: …" / "revoke session X: revoke session X: …". Return the wrapped errors verbatim.
Commit
ddb0807af8— logout: fix stale revokeCurrentFunc doc comment- The comment claimed the impl resolves its own data-API bearer; the caller now resolves the active context's core URL + token and binds them into the closure. Describe the actual contract.
Commit
394066405e— add--allto drain every saved login (context)entire logout --alliterates all saved contexts, revokes each context's current session server-side against its own core, removes each login locally, then clears the legacy keyring entry, so the machine ends fully logged out. Per-context failures warn but never abort the sweep; local removal always proceeds.
Commit
51486c980a— end-to-end test pinning the--all/--everywherematrix- Runs the real cobra logout command against two fake entire-core servers and asserts which revoke shape each context's core receives across all four quadrants:
logout→ active context, current sessionlogout --everywhere→ active context, all sessionslogout --all-contexts→ every context, current session eachlogout --all-contexts --everywhere→ every context, all sessions each
- This pins the command-layer mapping (
--everywhere→ revoke-all per core) that the runLogout/runLogoutAll unit tests can't reach, since they inject the revoke func directly.
- Runs the real cobra logout command against two fake entire-core servers and asserts which revoke shape each context's core receives across all four quadrants:
Important Points
- Environment Variables for API Endpoint Change:
Two env vars control it —activityreads its data host fromENTIRE_API_BASE_URLand its auth/login host fromENTIRE_AUTH_BASE_URL.
# Data API: where GET /api/v1/me/activity and /me/commits are served
export ENTIRE_API_BASE_URL=https://<your>.partial.to
# Auth/login host: device-flow login + keyring token key + STS exchange origin
export ENTIRE_AUTH_BASE_URL=https://<your>.partial.to
- JWT Refresh Note: If you receive a token-exchange error with your stored login JWT, tokens may be expired or revoked server-side. Re-run
entire loginto refresh. - Error Handling Best Practices: Implementing proper error messages for token exchange failures provides clearer guidance to users.