Control Plane Delete and Revoke Safety · Entire
Bottom line
Fixed trail #642's current finding — delete commands echoed the user's input instead of the resolved ULID. Committed on feat/control-plane-crud-gaps (rebased clean on origin/main).
- Finding:
repo delete(and the identical latent bug inorg/project delete) printedargs[0], so a name-based delete confirmed a name while the op used a ULID — ambiguous when names are reused. - Fix: added
resolvedRefLabel(ref, id)inresolveref.go→ rendersname (ULID)for names, bare ULID when the arg was already a ULID. Wired into all three delete success messages. - Tests: added
TestResolvedRefLabel;mise run fmt+lintclean (0 issues); resolveref tests pass. - Commit:
eb2c0db28e. Not pushed.
Notes:
fmt's--fixpass also stripped three now-unused//nolint:ireturndirectives incheckpoint/open.goandstrategy/manual_commit.go— unrelated to the finding, so I left them uncommitted in the working tree. Discard or commit separately as you prefer.- The other 3 findings on this trail are stale (org delete idempotency, missing
--force/confirmation, missing command-level wiring tests) and weren't touched — say the word if you want those addressed too. - Didn't resolve the finding in the tracker (blocked as an external write you didn't request). To close it:
entire trail finding resolve 019ef39b-6ce --trail 642 -m "fixed in eb2c0db28e".
Status
| Finding | Fix | Status |
|---|---|---|
019ef39b-6ce — success message shows arg, not resolved ULID |
resolvedRefLabel → name (ULID) on all deletes |
✅ resolved |
019ef4a6-14e — no confirmation / --force |
confirmation gate + --force/-f & --yes/-y; non-interactive refuses |
✅ resolved |
019ef4a6-20d — deletes not idempotent |
404 from delete → "not found; nothing to delete", exit 0 | ✅ resolved |
019ef4a6-2b7 — no command-level wiring tests |
TestControlPlaneDelete_Wiring (e2e-through-cobra) + TestConfirmControlPlaneDeletion |
✅ resolved |
(All four show stale freshness — expected, since the rebase changed the underlying blobs. That's a code-version marker, not a correctness signal; status is resolved.)
Branch
feat/control-plane-crud-gapsis now based onfeat/control-plane-friendly-names(verified: it's an ancestor), 13 commits.- The rebase reconciled crud-gaps against friendly-names' independent resolver rework: kept friendly-names' client-side
pickOrg/pickProjectresolver, dropped crud-gaps' server-side?name=variant, dropped the redundant nolint commit (already upstream), and adapted the seams (resolveOrgRefnow paginates; restoredisNotFound/resolvedRefLabel; added the test helper). - Local verification before push:
go build ./...,go vet,mise run lint(0 issues), fullcmd/entire/cliunit tests pass. Integration tests left to CI per your call. - Force-pushed (history was rewritten by the rebase). Backup tag
backup/crud-gaps-on-main-…exists locally if you need the pre-rebase state.