Repository navigation
feat(auth): capture ChurchTools host at login (no hardcoded default) - #16
Merged
Merged
Conversation
The host is now bound to the login: captured via `ct auth login --host <url>`
(or CT_HOST) and stored with the token in the Keychain as one JSON blob.
resolveConfig is async and resolves host from CT_HOST env → stored login, with
no fallback — commands fail with a clear 'run ct auth login --host' message
instead of silently targeting the eqrm prod default.
- tokenStore: storeCredentials/readCredentials/clearCredentials ({host, token});
parseCredentials rejects legacy bare-token values (requires re-login).
- config: async resolveConfig(env, readHost) + normalizeHost; injectable for tests.
- CtClient no longer defaults its config (callers pass it).
- auth login gains -H/--host; status/logout updated.
- Tests: config precedence + parseCredentials; adopt test sets CT_HOST.
Migration: re-run `ct auth login --host <url> --token <token>` once.
…n entry, simplify status guard - session.ts: 'Not logged in' hint now includes the required --host - tokenStore: clearCredentials also deletes the pre-host 'login-token' entry so an upgrade never orphans a secret - auth status: reuse readToken() instead of re-implementing its env→stored precedence
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Captures the ChurchTools host at login instead of leaning on a hardcoded prod default.
Follow-up to the host concern raised while verifying #15 (Phase 4). Stacked on
feat/phase-4-apply-destroy— retarget tomainonce #15 merges.What changes
ct auth login --host <url> --token <token>— the host is verified and stored with the token (bound together) in the macOS Keychain as one JSON blob.resolveConfigis now async and resolves the host as:CT_HOSTenv → stored login host → error (run ct auth login --host …). No hardcodedeqrm.church.toolsdefault — the generic tool no longer ships one org's host.CtClientno longer defaults its config (callers pass it); all command call sitesawait resolveConfig().auth status/logoutupdated for the host+token credential.Behaviour
Migration
The credential is stored under a new Keychain entry with a JSON
{host, token}value; a legacy bare-token value is rejected byparseCredentials. Re-runct auth login --host <url> --token <token>once after upgrading.Testing
140 tests pass. New:
resolveConfigprecedence (env > stored > error, injectable reader) andparseCredentials(valid / legacy-bare-token / missing-field). Verified read-only: the no-host refusal,loginrequiring host then token, and--hostin--help.tsc/eslint/buildclean.https://claude.ai/code/session_017tFJu7SrS5uLdit5FtXiwS