Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,9 +14,12 @@ export const createCreateApiKeyCredentialProviderHandler = (core: Core, io: AppI
description: "create an API key credential provider",
flags: [
flag("name", "the name of the API key credential provider", z.string().optional()),
flag("api-key", "the API key value (inline, file://path, or -)", z.string().optional(), {
sensitive: true,
}),
flag(
"api-key",
"the API key (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{ sensitive: true },
),
flag(
"api-key-secret-reference",
'external secret reference JSON: {"secretId":"<arn>","jsonKey":"<key>"}',
Expand DownExpand Up@@ -44,7 +47,7 @@ export const createCreateApiKeyCredentialProviderHandler = (core: Core, io: AppI
}

const resolver = new SourceResolver({ stdin: io.stdin });
const apiKey = await resolver.resolveText("api-key", flags["api-key"]);
const apiKey = await resolver.resolveSecret("api-key", flags["api-key"]);
const apiKeySecretConfig = hasSecretRef
? parseSecretReference("api-key-secret-reference", flags["api-key-secret-reference"]!)
: undefined;
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,9 +14,12 @@ export const createUpdateApiKeyCredentialProviderHandler = (core: Core, io: AppI
description: "update an API key credential provider",
flags: [
flag("name", "the name of the API key credential provider", z.string().optional()),
flag("api-key", "the new API key value (inline, file://path, or -)", z.string().optional(), {
sensitive: true,
}),
flag(
"api-key",
"the new API key (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{ sensitive: true },
),
flag(
"api-key-secret-reference",
'external secret reference JSON: {"secretId":"<arn>","jsonKey":"<key>"}',
Expand DownExpand Up@@ -57,7 +60,7 @@ export const createUpdateApiKeyCredentialProviderHandler = (core: Core, io: AppI
}

const resolver = new SourceResolver({ stdin: io.stdin });
const apiKey = await resolver.resolveText("api-key", flags["api-key"]);
const apiKey = await resolver.resolveSecret("api-key", flags["api-key"]);
const apiKeySecretConfig = hasSecretRef
? parseSecretReference("api-key-secret-reference", flags["api-key-secret-reference"]!)
: undefined;
Expand Down
74 changes: 48 additions & 26 deletions src/handlers/identity/identity.test.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,8 +32,8 @@ function createFixtureCore(): CoreClient {
});
}

async function run(args: string[]): Promise<string> {
const io = testIO();
async function run(args: string[], stdin?: string): Promise<string> {
const io = testIO({ stdin });
const root = createRootHandler(createFixtureCore(), {
io: io.io,
logger: createSilentLogger(),
Expand DownExpand Up@@ -101,29 +101,35 @@ describe("api-key-credential-provider TUI dispatch", () => {

describe("api-key-credential-provider CRUDL", () => {
test("creates an API key credential provider", async () => {
const stdout = await run([
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
const stdout = await run(
[
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
"-",
],
"test-api-key-value",
]);
);

matchGolden(FIXTURES, "create.golden.json", stdout);
});

test("creates a second API key credential provider for pagination", async () => {
const stdout = await run([
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--api-key",
const stdout = await run(
[
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--api-key",
"-",
],
"test-api-key-value-2",
]);
);

matchGolden(FIXTURES, "create-2.golden.json", stdout);
});
Expand DownExpand Up@@ -176,15 +182,18 @@ describe("api-key-credential-provider CRUDL", () => {
});

test("updates an API key credential provider", async () => {
const stdout = await run([
"identity",
"api-key-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
const stdout = await run(
[
"identity",
"api-key-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
"-",
],
"updated-api-key-value",
]);
);

matchGolden(FIXTURES, "update.golden.json", stdout);
expect(JSON.parse(stdout).name).toBe(FIXTURE_PROVIDER_NAME);
Expand DownExpand Up@@ -301,6 +310,19 @@ describe("api-key-credential-provider CRUDL", () => {
],
/mutually exclusive/,
],
[
"create: --api-key with an inline value",
[
"identity",
"api-key-credential-provider",
"create",
"--name",
"x",
"--api-key",
"sk-inline",
],
/file:\/\//,
],
] as const)("rejects invalid secret input for `%s`", async (_label, args, message) => {
expect(run([...args])).rejects.toThrow(message);
});
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -23,11 +23,9 @@ export const createCreateOauth2CredentialProviderHandler = (core: Core, io: AppI
flag("vendor", "the OAuth2 vendor (e.g. CustomOauth2, GithubOauth2)", z.string().optional()),
flag(
"client-secret",
"the client secret (inline, file://path, or -)",
"the client secret (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{
sensitive: true,
},
{ sensitive: true },
),
flag(
"client-secret-reference",
Expand DownExpand Up@@ -81,7 +79,7 @@ export const createCreateOauth2CredentialProviderHandler = (core: Core, io: AppI
validateProviderConfigMode(providerConfigMode, vendor);

const resolver = new SourceResolver({ stdin: io.stdin });
const clientSecret = await resolver.resolveText("client-secret", flags["client-secret"]);
const clientSecret = await resolver.resolveSecret("client-secret", flags["client-secret"]);

const clientSecretConfig = hasSecretRef
? parseSecretReference("client-secret-reference", flags["client-secret-reference"]!)
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,8 +32,8 @@ function createFixtureCore(): CoreClient {
});
}

async function run(args: string[]): Promise<string> {
const io = testIO();
async function run(args: string[], stdin?: string): Promise<string> {
const io = testIO({ stdin });
const root = createRootHandler(createFixtureCore(), {
io: io.io,
logger: createSilentLogger(),
Expand All@@ -46,41 +46,47 @@ async function run(args: string[]): Promise<string> {

describe("oauth2-credential-provider CRUDL", () => {
test("creates an OAuth2 credential provider", async () => {
const stdout = await run([
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
const stdout = await run(
[
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
"-",
],
"fixture-secret",
]);
);

matchGolden(FIXTURES, "create.golden.json", stdout);
});

test("creates a second OAuth2 credential provider for pagination", async () => {
const stdout = await run([
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id-2",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
const stdout = await run(
[
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id-2",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
"-",
],
"fixture-secret-2",
]);
);

matchGolden(FIXTURES, "create-2.golden.json", stdout);
});
Expand DownExpand Up@@ -133,21 +139,24 @@ describe("oauth2-credential-provider CRUDL", () => {
});

test("updates an OAuth2 credential provider", async () => {
const stdout = await run([
"identity",
"oauth2-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"updated-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
const stdout = await run(
[
"identity",
"oauth2-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"updated-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
"-",
],
"updated-secret",
]);
);

matchGolden(FIXTURES, "update.golden.json", stdout);
expect(JSON.parse(stdout).name).toBe(FIXTURE_PROVIDER_NAME);
Expand Down
23 changes: 21 additions & 2 deletions src/handlers/identity/oauth2-credential-provider/oauth2.test.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -67,8 +67,9 @@ const UPDATE_RESPONSE = {
async function run(
args: string[],
core = new TestCoreClient(),
stdin?: string,
): Promise<{ core: TestCoreClient; stdout: string }> {
const io = testIO();
const io = testIO({ stdin });
const root = createRootHandler(core, {
io: io.io,
logger: createSilentLogger(),
Expand DownExpand Up@@ -287,6 +288,23 @@ describe("oauth2-credential-provider flag validation", () => {
],
/requires one of --discovery-url or --authorization-server-metadata/,
],
[
"create: --client-secret with an inline value",
[
"identity",
"oauth2-credential-provider",
"create",
"--name",
"x",
"--vendor",
"CustomOauth2",
"--discovery-url",
"https://example.com",
"--client-secret",
"s-inline",
],
/file:\/\//,
],
] as const)("enforces vendor/config-mode rules for `%s`", async (_label, args, message) => {
expect(run([...args])).rejects.toThrow(message);
});
Expand DownExpand Up@@ -477,9 +495,10 @@ describe("OAuth2 update handler", () => {
PROVIDER_NAME,
...vendorArgs,
"--client-secret",
"updated-secret",
"-",
],
core,
"updated-secret",
);

const updateCall = core.identity.calls[1];
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -45,11 +45,9 @@ export const createUpdateOauth2CredentialProviderHandler = (core: Core, io: AppI
flag("vendor", "the OAuth2 vendor", z.string().optional()),
flag(
"client-secret",
"the client secret (inline, file://path, or -)",
"the client secret (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{
sensitive: true,
},
{ sensitive: true },
),
flag(
"client-secret-reference",
Expand DownExpand Up@@ -131,7 +129,7 @@ export const createUpdateOauth2CredentialProviderHandler = (core: Core, io: AppI
validateCompleteConfigKey(providerConfigMode, existing.oauth2ProviderConfigOutput);

const resolver = new SourceResolver({ stdin: io.stdin });
const clientSecret = await resolver.resolveText("client-secret", flags["client-secret"]);
const clientSecret = await resolver.resolveSecret("client-secret", flags["client-secret"]);

const clientSecretConfig = hasSecretRef
? parseSecretReference("client-secret-reference", flags["client-secret-reference"]!)
Expand Down
4 changes: 4 additions & 0 deletions src/handlers/project/add/runtime/index.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -325,6 +325,10 @@ describe("project add runtime", () => {
"--api-key is only available on template path",
["--name", "my_agent", ...byo, "--api-key", "-"],
],
[
"--api-key rejects an inline secret value",
["--name", "my_agent", ...template, "--api-key", "sk-inline"],
],
[
"invalid memory JSON schema",
["--name", "my_agent", ...template, "--memory", '{"mode":"invalid"}'],
Expand Down
2 changes: 1 addition & 1 deletion src/handlers/project/add/runtime/index.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -151,7 +151,7 @@ export const createAddRuntimeHandler = (config: AddProjectResourceConfig) =>
const entrypoint = flags.entrypoint ?? "main.py";

const source = new SourceResolver({ stdin: config.io.stdin });
const apiKey = await source.resolveText("api-key", flags["api-key"]);
const apiKey = await source.resolveSecret("api-key", flags["api-key"]);

if (flags["custom-docker-build-args"] && !flags.dockerfile && !flags["build-context-path"])
throw new InputValidationError(
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,9 +14,12 @@ export const createCreateApiKeyCredentialProviderHandler = (core: Core, io: AppI
description: "create an API key credential provider",
flags: [
flag("name", "the name of the API key credential provider", z.string().optional()),
flag("api-key", "the API key value (inline, file://path, or -)", z.string().optional(), {
sensitive: true,
}),
flag(
"api-key",
"the API key (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{ sensitive: true },
),
flag(
"api-key-secret-reference",
'external secret reference JSON: {"secretId":"<arn>","jsonKey":"<key>"}',
Expand DownExpand Up@@ -44,7 +47,7 @@ export const createCreateApiKeyCredentialProviderHandler = (core: Core, io: AppI
}

const resolver = new SourceResolver({ stdin: io.stdin });
const apiKey = await resolver.resolveText("api-key", flags["api-key"]);
const apiKey = await resolver.resolveSecret("api-key", flags["api-key"]);
const apiKeySecretConfig = hasSecretRef
? parseSecretReference("api-key-secret-reference", flags["api-key-secret-reference"]!)
: undefined;
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,9 +14,12 @@ export const createUpdateApiKeyCredentialProviderHandler = (core: Core, io: AppI
description: "update an API key credential provider",
flags: [
flag("name", "the name of the API key credential provider", z.string().optional()),
flag("api-key", "the new API key value (inline, file://path, or -)", z.string().optional(), {
sensitive: true,
}),
flag(
"api-key",
"the new API key (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{ sensitive: true },
),
flag(
"api-key-secret-reference",
'external secret reference JSON: {"secretId":"<arn>","jsonKey":"<key>"}',
Expand DownExpand Up@@ -57,7 +60,7 @@ export const createUpdateApiKeyCredentialProviderHandler = (core: Core, io: AppI
}

const resolver = new SourceResolver({ stdin: io.stdin });
const apiKey = await resolver.resolveText("api-key", flags["api-key"]);
const apiKey = await resolver.resolveSecret("api-key", flags["api-key"]);
const apiKeySecretConfig = hasSecretRef
? parseSecretReference("api-key-secret-reference", flags["api-key-secret-reference"]!)
: undefined;
Expand Down
74 changes: 48 additions & 26 deletions src/handlers/identity/identity.test.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,8 +32,8 @@ function createFixtureCore(): CoreClient {
});
}

async function run(args: string[]): Promise<string> {
const io = testIO();
async function run(args: string[], stdin?: string): Promise<string> {
const io = testIO({ stdin });
const root = createRootHandler(createFixtureCore(), {
io: io.io,
logger: createSilentLogger(),
Expand DownExpand Up@@ -101,29 +101,35 @@ describe("api-key-credential-provider TUI dispatch", () => {

describe("api-key-credential-provider CRUDL", () => {
test("creates an API key credential provider", async () => {
const stdout = await run([
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
const stdout = await run(
[
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
"-",
],
"test-api-key-value",
]);
);

matchGolden(FIXTURES, "create.golden.json", stdout);
});

test("creates a second API key credential provider for pagination", async () => {
const stdout = await run([
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--api-key",
const stdout = await run(
[
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--api-key",
"-",
],
"test-api-key-value-2",
]);
);

matchGolden(FIXTURES, "create-2.golden.json", stdout);
});
Expand DownExpand Up@@ -176,15 +182,18 @@ describe("api-key-credential-provider CRUDL", () => {
});

test("updates an API key credential provider", async () => {
const stdout = await run([
"identity",
"api-key-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
const stdout = await run(
[
"identity",
"api-key-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
"-",
],
"updated-api-key-value",
]);
);

matchGolden(FIXTURES, "update.golden.json", stdout);
expect(JSON.parse(stdout).name).toBe(FIXTURE_PROVIDER_NAME);
Expand DownExpand Up@@ -301,6 +310,19 @@ describe("api-key-credential-provider CRUDL", () => {
],
/mutually exclusive/,
],
[
"create: --api-key with an inline value",
[
"identity",
"api-key-credential-provider",
"create",
"--name",
"x",
"--api-key",
"sk-inline",
],
/file:\/\//,
],
] as const)("rejects invalid secret input for `%s`", async (_label, args, message) => {
expect(run([...args])).rejects.toThrow(message);
});
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -23,11 +23,9 @@ export const createCreateOauth2CredentialProviderHandler = (core: Core, io: AppI
flag("vendor", "the OAuth2 vendor (e.g. CustomOauth2, GithubOauth2)", z.string().optional()),
flag(
"client-secret",
"the client secret (inline, file://path, or -)",
"the client secret (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{
sensitive: true,
},
{ sensitive: true },
),
flag(
"client-secret-reference",
Expand DownExpand Up@@ -81,7 +79,7 @@ export const createCreateOauth2CredentialProviderHandler = (core: Core, io: AppI
validateProviderConfigMode(providerConfigMode, vendor);

const resolver = new SourceResolver({ stdin: io.stdin });
const clientSecret = await resolver.resolveText("client-secret", flags["client-secret"]);
const clientSecret = await resolver.resolveSecret("client-secret", flags["client-secret"]);

const clientSecretConfig = hasSecretRef
? parseSecretReference("client-secret-reference", flags["client-secret-reference"]!)
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,8 +32,8 @@ function createFixtureCore(): CoreClient {
});
}

async function run(args: string[]): Promise<string> {
const io = testIO();
async function run(args: string[], stdin?: string): Promise<string> {
const io = testIO({ stdin });
const root = createRootHandler(createFixtureCore(), {
io: io.io,
logger: createSilentLogger(),
Expand All@@ -46,41 +46,47 @@ async function run(args: string[]): Promise<string> {

describe("oauth2-credential-provider CRUDL", () => {
test("creates an OAuth2 credential provider", async () => {
const stdout = await run([
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
const stdout = await run(
[
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
"-",
],
"fixture-secret",
]);
);

matchGolden(FIXTURES, "create.golden.json", stdout);
});

test("creates a second OAuth2 credential provider for pagination", async () => {
const stdout = await run([
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id-2",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
const stdout = await run(
[
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id-2",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
"-",
],
"fixture-secret-2",
]);
);

matchGolden(FIXTURES, "create-2.golden.json", stdout);
});
Expand DownExpand Up@@ -133,21 +139,24 @@ describe("oauth2-credential-provider CRUDL", () => {
});

test("updates an OAuth2 credential provider", async () => {
const stdout = await run([
"identity",
"oauth2-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"updated-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
const stdout = await run(
[
"identity",
"oauth2-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"updated-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
"-",
],
"updated-secret",
]);
);

matchGolden(FIXTURES, "update.golden.json", stdout);
expect(JSON.parse(stdout).name).toBe(FIXTURE_PROVIDER_NAME);
Expand Down
23 changes: 21 additions & 2 deletions src/handlers/identity/oauth2-credential-provider/oauth2.test.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -67,8 +67,9 @@ const UPDATE_RESPONSE = {
async function run(
args: string[],
core = new TestCoreClient(),
stdin?: string,
): Promise<{ core: TestCoreClient; stdout: string }> {
const io = testIO();
const io = testIO({ stdin });
const root = createRootHandler(core, {
io: io.io,
logger: createSilentLogger(),
Expand DownExpand Up@@ -287,6 +288,23 @@ describe("oauth2-credential-provider flag validation", () => {
],
/requires one of --discovery-url or --authorization-server-metadata/,
],
[
"create: --client-secret with an inline value",
[
"identity",
"oauth2-credential-provider",
"create",
"--name",
"x",
"--vendor",
"CustomOauth2",
"--discovery-url",
"https://example.com",
"--client-secret",
"s-inline",
],
/file:\/\//,
],
] as const)("enforces vendor/config-mode rules for `%s`", async (_label, args, message) => {
expect(run([...args])).rejects.toThrow(message);
});
Expand DownExpand Up@@ -477,9 +495,10 @@ describe("OAuth2 update handler", () => {
PROVIDER_NAME,
...vendorArgs,
"--client-secret",
"updated-secret",
"-",
],
core,
"updated-secret",
);

const updateCall = core.identity.calls[1];
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -45,11 +45,9 @@ export const createUpdateOauth2CredentialProviderHandler = (core: Core, io: AppI
flag("vendor", "the OAuth2 vendor", z.string().optional()),
flag(
"client-secret",
"the client secret (inline, file://path, or -)",
"the client secret (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{
sensitive: true,
},
{ sensitive: true },
),
flag(
"client-secret-reference",
Expand DownExpand Up@@ -131,7 +129,7 @@ export const createUpdateOauth2CredentialProviderHandler = (core: Core, io: AppI
validateCompleteConfigKey(providerConfigMode, existing.oauth2ProviderConfigOutput);

const resolver = new SourceResolver({ stdin: io.stdin });
const clientSecret = await resolver.resolveText("client-secret", flags["client-secret"]);
const clientSecret = await resolver.resolveSecret("client-secret", flags["client-secret"]);

const clientSecretConfig = hasSecretRef
? parseSecretReference("client-secret-reference", flags["client-secret-reference"]!)
Expand Down
4 changes: 4 additions & 0 deletions src/handlers/project/add/runtime/index.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -325,6 +325,10 @@ describe("project add runtime", () => {
"--api-key is only available on template path",
["--name", "my_agent", ...byo, "--api-key", "-"],
],
[
"--api-key rejects an inline secret value",
["--name", "my_agent", ...template, "--api-key", "sk-inline"],
],
[
"invalid memory JSON schema",
["--name", "my_agent", ...template, "--memory", '{"mode":"invalid"}'],
Expand Down
2 changes: 1 addition & 1 deletion src/handlers/project/add/runtime/index.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -151,7 +151,7 @@ export const createAddRuntimeHandler = (config: AddProjectResourceConfig) =>
const entrypoint = flags.entrypoint ?? "main.py";

const source = new SourceResolver({ stdin: config.io.stdin });
const apiKey = await source.resolveText("api-key", flags["api-key"]);
const apiKey = await source.resolveSecret("api-key", flags["api-key"]);

if (flags["custom-docker-build-args"] && !flags.dockerfile && !flags["build-context-path"])
throw new InputValidationError(
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,9 +14,12 @@ export const createCreateApiKeyCredentialProviderHandler = (core: Core, io: AppI
description: "create an API key credential provider",
flags: [
flag("name", "the name of the API key credential provider", z.string().optional()),
flag("api-key", "the API key value (inline, file://path, or -)", z.string().optional(), {
sensitive: true,
}),
flag(
"api-key",
"the API key (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{ sensitive: true },
),
flag(
"api-key-secret-reference",
'external secret reference JSON: {"secretId":"<arn>","jsonKey":"<key>"}',
Expand DownExpand Up@@ -44,7 +47,7 @@ export const createCreateApiKeyCredentialProviderHandler = (core: Core, io: AppI
}

const resolver = new SourceResolver({ stdin: io.stdin });
const apiKey = await resolver.resolveText("api-key", flags["api-key"]);
const apiKey = await resolver.resolveSecret("api-key", flags["api-key"]);
const apiKeySecretConfig = hasSecretRef
? parseSecretReference("api-key-secret-reference", flags["api-key-secret-reference"]!)
: undefined;
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,9 +14,12 @@ export const createUpdateApiKeyCredentialProviderHandler = (core: Core, io: AppI
description: "update an API key credential provider",
flags: [
flag("name", "the name of the API key credential provider", z.string().optional()),
flag("api-key", "the new API key value (inline, file://path, or -)", z.string().optional(), {
sensitive: true,
}),
flag(
"api-key",
"the new API key (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{ sensitive: true },
),
flag(
"api-key-secret-reference",
'external secret reference JSON: {"secretId":"<arn>","jsonKey":"<key>"}',
Expand DownExpand Up@@ -57,7 +60,7 @@ export const createUpdateApiKeyCredentialProviderHandler = (core: Core, io: AppI
}

const resolver = new SourceResolver({ stdin: io.stdin });
const apiKey = await resolver.resolveText("api-key", flags["api-key"]);
const apiKey = await resolver.resolveSecret("api-key", flags["api-key"]);
const apiKeySecretConfig = hasSecretRef
? parseSecretReference("api-key-secret-reference", flags["api-key-secret-reference"]!)
: undefined;
Expand Down
74 changes: 48 additions & 26 deletions src/handlers/identity/identity.test.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,8 +32,8 @@ function createFixtureCore(): CoreClient {
});
}

async function run(args: string[]): Promise<string> {
const io = testIO();
async function run(args: string[], stdin?: string): Promise<string> {
const io = testIO({ stdin });
const root = createRootHandler(createFixtureCore(), {
io: io.io,
logger: createSilentLogger(),
Expand DownExpand Up@@ -101,29 +101,35 @@ describe("api-key-credential-provider TUI dispatch", () => {

describe("api-key-credential-provider CRUDL", () => {
test("creates an API key credential provider", async () => {
const stdout = await run([
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
const stdout = await run(
[
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
"-",
],
"test-api-key-value",
]);
);

matchGolden(FIXTURES, "create.golden.json", stdout);
});

test("creates a second API key credential provider for pagination", async () => {
const stdout = await run([
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--api-key",
const stdout = await run(
[
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--api-key",
"-",
],
"test-api-key-value-2",
]);
);

matchGolden(FIXTURES, "create-2.golden.json", stdout);
});
Expand DownExpand Up@@ -176,15 +182,18 @@ describe("api-key-credential-provider CRUDL", () => {
});

test("updates an API key credential provider", async () => {
const stdout = await run([
"identity",
"api-key-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
const stdout = await run(
[
"identity",
"api-key-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
"-",
],
"updated-api-key-value",
]);
);

matchGolden(FIXTURES, "update.golden.json", stdout);
expect(JSON.parse(stdout).name).toBe(FIXTURE_PROVIDER_NAME);
Expand DownExpand Up@@ -301,6 +310,19 @@ describe("api-key-credential-provider CRUDL", () => {
],
/mutually exclusive/,
],
[
"create: --api-key with an inline value",
[
"identity",
"api-key-credential-provider",
"create",
"--name",
"x",
"--api-key",
"sk-inline",
],
/file:\/\//,
],
] as const)("rejects invalid secret input for `%s`", async (_label, args, message) => {
expect(run([...args])).rejects.toThrow(message);
});
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -23,11 +23,9 @@ export const createCreateOauth2CredentialProviderHandler = (core: Core, io: AppI
flag("vendor", "the OAuth2 vendor (e.g. CustomOauth2, GithubOauth2)", z.string().optional()),
flag(
"client-secret",
"the client secret (inline, file://path, or -)",
"the client secret (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{
sensitive: true,
},
{ sensitive: true },
),
flag(
"client-secret-reference",
Expand DownExpand Up@@ -81,7 +79,7 @@ export const createCreateOauth2CredentialProviderHandler = (core: Core, io: AppI
validateProviderConfigMode(providerConfigMode, vendor);

const resolver = new SourceResolver({ stdin: io.stdin });
const clientSecret = await resolver.resolveText("client-secret", flags["client-secret"]);
const clientSecret = await resolver.resolveSecret("client-secret", flags["client-secret"]);

const clientSecretConfig = hasSecretRef
? parseSecretReference("client-secret-reference", flags["client-secret-reference"]!)
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,8 +32,8 @@ function createFixtureCore(): CoreClient {
});
}

async function run(args: string[]): Promise<string> {
const io = testIO();
async function run(args: string[], stdin?: string): Promise<string> {
const io = testIO({ stdin });
const root = createRootHandler(createFixtureCore(), {
io: io.io,
logger: createSilentLogger(),
Expand All@@ -46,41 +46,47 @@ async function run(args: string[]): Promise<string> {

describe("oauth2-credential-provider CRUDL", () => {
test("creates an OAuth2 credential provider", async () => {
const stdout = await run([
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
const stdout = await run(
[
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
"-",
],
"fixture-secret",
]);
);

matchGolden(FIXTURES, "create.golden.json", stdout);
});

test("creates a second OAuth2 credential provider for pagination", async () => {
const stdout = await run([
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id-2",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
const stdout = await run(
[
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id-2",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
"-",
],
"fixture-secret-2",
]);
);

matchGolden(FIXTURES, "create-2.golden.json", stdout);
});
Expand DownExpand Up@@ -133,21 +139,24 @@ describe("oauth2-credential-provider CRUDL", () => {
});

test("updates an OAuth2 credential provider", async () => {
const stdout = await run([
"identity",
"oauth2-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"updated-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
const stdout = await run(
[
"identity",
"oauth2-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"updated-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
"-",
],
"updated-secret",
]);
);

matchGolden(FIXTURES, "update.golden.json", stdout);
expect(JSON.parse(stdout).name).toBe(FIXTURE_PROVIDER_NAME);
Expand Down
23 changes: 21 additions & 2 deletions src/handlers/identity/oauth2-credential-provider/oauth2.test.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -67,8 +67,9 @@ const UPDATE_RESPONSE = {
async function run(
args: string[],
core = new TestCoreClient(),
stdin?: string,
): Promise<{ core: TestCoreClient; stdout: string }> {
const io = testIO();
const io = testIO({ stdin });
const root = createRootHandler(core, {
io: io.io,
logger: createSilentLogger(),
Expand DownExpand Up@@ -287,6 +288,23 @@ describe("oauth2-credential-provider flag validation", () => {
],
/requires one of --discovery-url or --authorization-server-metadata/,
],
[
"create: --client-secret with an inline value",
[
"identity",
"oauth2-credential-provider",
"create",
"--name",
"x",
"--vendor",
"CustomOauth2",
"--discovery-url",
"https://example.com",
"--client-secret",
"s-inline",
],
/file:\/\//,
],
] as const)("enforces vendor/config-mode rules for `%s`", async (_label, args, message) => {
expect(run([...args])).rejects.toThrow(message);
});
Expand DownExpand Up@@ -477,9 +495,10 @@ describe("OAuth2 update handler", () => {
PROVIDER_NAME,
...vendorArgs,
"--client-secret",
"updated-secret",
"-",
],
core,
"updated-secret",
);

const updateCall = core.identity.calls[1];
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -45,11 +45,9 @@ export const createUpdateOauth2CredentialProviderHandler = (core: Core, io: AppI
flag("vendor", "the OAuth2 vendor", z.string().optional()),
flag(
"client-secret",
"the client secret (inline, file://path, or -)",
"the client secret (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{
sensitive: true,
},
{ sensitive: true },
),
flag(
"client-secret-reference",
Expand DownExpand Up@@ -131,7 +129,7 @@ export const createUpdateOauth2CredentialProviderHandler = (core: Core, io: AppI
validateCompleteConfigKey(providerConfigMode, existing.oauth2ProviderConfigOutput);

const resolver = new SourceResolver({ stdin: io.stdin });
const clientSecret = await resolver.resolveText("client-secret", flags["client-secret"]);
const clientSecret = await resolver.resolveSecret("client-secret", flags["client-secret"]);

const clientSecretConfig = hasSecretRef
? parseSecretReference("client-secret-reference", flags["client-secret-reference"]!)
Expand Down
4 changes: 4 additions & 0 deletions src/handlers/project/add/runtime/index.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -325,6 +325,10 @@ describe("project add runtime", () => {
"--api-key is only available on template path",
["--name", "my_agent", ...byo, "--api-key", "-"],
],
[
"--api-key rejects an inline secret value",
["--name", "my_agent", ...template, "--api-key", "sk-inline"],
],
[
"invalid memory JSON schema",
["--name", "my_agent", ...template, "--memory", '{"mode":"invalid"}'],
Expand Down
2 changes: 1 addition & 1 deletion src/handlers/project/add/runtime/index.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -151,7 +151,7 @@ export const createAddRuntimeHandler = (config: AddProjectResourceConfig) =>
const entrypoint = flags.entrypoint ?? "main.py";

const source = new SourceResolver({ stdin: config.io.stdin });
const apiKey = await source.resolveText("api-key", flags["api-key"]);
const apiKey = await source.resolveSecret("api-key", flags["api-key"]);

if (flags["custom-docker-build-args"] && !flags.dockerfile && !flags["build-context-path"])
throw new InputValidationError(
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,9 +14,12 @@ export const createCreateApiKeyCredentialProviderHandler = (core: Core, io: AppI
description: "create an API key credential provider",
flags: [
flag("name", "the name of the API key credential provider", z.string().optional()),
flag("api-key", "the API key value (inline, file://path, or -)", z.string().optional(), {
sensitive: true,
}),
flag(
"api-key",
"the API key (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{ sensitive: true },
),
flag(
"api-key-secret-reference",
'external secret reference JSON: {"secretId":"<arn>","jsonKey":"<key>"}',
Expand DownExpand Up@@ -44,7 +47,7 @@ export const createCreateApiKeyCredentialProviderHandler = (core: Core, io: AppI
}

const resolver = new SourceResolver({ stdin: io.stdin });
const apiKey = await resolver.resolveText("api-key", flags["api-key"]);
const apiKey = await resolver.resolveSecret("api-key", flags["api-key"]);
const apiKeySecretConfig = hasSecretRef
? parseSecretReference("api-key-secret-reference", flags["api-key-secret-reference"]!)
: undefined;
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,9 +14,12 @@ export const createUpdateApiKeyCredentialProviderHandler = (core: Core, io: AppI
description: "update an API key credential provider",
flags: [
flag("name", "the name of the API key credential provider", z.string().optional()),
flag("api-key", "the new API key value (inline, file://path, or -)", z.string().optional(), {
sensitive: true,
}),
flag(
"api-key",
"the new API key (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{ sensitive: true },
),
flag(
"api-key-secret-reference",
'external secret reference JSON: {"secretId":"<arn>","jsonKey":"<key>"}',
Expand DownExpand Up@@ -57,7 +60,7 @@ export const createUpdateApiKeyCredentialProviderHandler = (core: Core, io: AppI
}

const resolver = new SourceResolver({ stdin: io.stdin });
const apiKey = await resolver.resolveText("api-key", flags["api-key"]);
const apiKey = await resolver.resolveSecret("api-key", flags["api-key"]);
const apiKeySecretConfig = hasSecretRef
? parseSecretReference("api-key-secret-reference", flags["api-key-secret-reference"]!)
: undefined;
Expand Down
74 changes: 48 additions & 26 deletions src/handlers/identity/identity.test.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,8 +32,8 @@ function createFixtureCore(): CoreClient {
});
}

async function run(args: string[]): Promise<string> {
const io = testIO();
async function run(args: string[], stdin?: string): Promise<string> {
const io = testIO({ stdin });
const root = createRootHandler(createFixtureCore(), {
io: io.io,
logger: createSilentLogger(),
Expand DownExpand Up@@ -101,29 +101,35 @@ describe("api-key-credential-provider TUI dispatch", () => {

describe("api-key-credential-provider CRUDL", () => {
test("creates an API key credential provider", async () => {
const stdout = await run([
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
const stdout = await run(
[
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
"-",
],
"test-api-key-value",
]);
);

matchGolden(FIXTURES, "create.golden.json", stdout);
});

test("creates a second API key credential provider for pagination", async () => {
const stdout = await run([
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--api-key",
const stdout = await run(
[
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--api-key",
"-",
],
"test-api-key-value-2",
]);
);

matchGolden(FIXTURES, "create-2.golden.json", stdout);
});
Expand DownExpand Up@@ -176,15 +182,18 @@ describe("api-key-credential-provider CRUDL", () => {
});

test("updates an API key credential provider", async () => {
const stdout = await run([
"identity",
"api-key-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
const stdout = await run(
[
"identity",
"api-key-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
"-",
],
"updated-api-key-value",
]);
);

matchGolden(FIXTURES, "update.golden.json", stdout);
expect(JSON.parse(stdout).name).toBe(FIXTURE_PROVIDER_NAME);
Expand DownExpand Up@@ -301,6 +310,19 @@ describe("api-key-credential-provider CRUDL", () => {
],
/mutually exclusive/,
],
[
"create: --api-key with an inline value",
[
"identity",
"api-key-credential-provider",
"create",
"--name",
"x",
"--api-key",
"sk-inline",
],
/file:\/\//,
],
] as const)("rejects invalid secret input for `%s`", async (_label, args, message) => {
expect(run([...args])).rejects.toThrow(message);
});
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -23,11 +23,9 @@ export const createCreateOauth2CredentialProviderHandler = (core: Core, io: AppI
flag("vendor", "the OAuth2 vendor (e.g. CustomOauth2, GithubOauth2)", z.string().optional()),
flag(
"client-secret",
"the client secret (inline, file://path, or -)",
"the client secret (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{
sensitive: true,
},
{ sensitive: true },
),
flag(
"client-secret-reference",
Expand DownExpand Up@@ -81,7 +79,7 @@ export const createCreateOauth2CredentialProviderHandler = (core: Core, io: AppI
validateProviderConfigMode(providerConfigMode, vendor);

const resolver = new SourceResolver({ stdin: io.stdin });
const clientSecret = await resolver.resolveText("client-secret", flags["client-secret"]);
const clientSecret = await resolver.resolveSecret("client-secret", flags["client-secret"]);

const clientSecretConfig = hasSecretRef
? parseSecretReference("client-secret-reference", flags["client-secret-reference"]!)
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,8 +32,8 @@ function createFixtureCore(): CoreClient {
});
}

async function run(args: string[]): Promise<string> {
const io = testIO();
async function run(args: string[], stdin?: string): Promise<string> {
const io = testIO({ stdin });
const root = createRootHandler(createFixtureCore(), {
io: io.io,
logger: createSilentLogger(),
Expand All@@ -46,41 +46,47 @@ async function run(args: string[]): Promise<string> {

describe("oauth2-credential-provider CRUDL", () => {
test("creates an OAuth2 credential provider", async () => {
const stdout = await run([
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
const stdout = await run(
[
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
"-",
],
"fixture-secret",
]);
);

matchGolden(FIXTURES, "create.golden.json", stdout);
});

test("creates a second OAuth2 credential provider for pagination", async () => {
const stdout = await run([
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id-2",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
const stdout = await run(
[
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id-2",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
"-",
],
"fixture-secret-2",
]);
);

matchGolden(FIXTURES, "create-2.golden.json", stdout);
});
Expand DownExpand Up@@ -133,21 +139,24 @@ describe("oauth2-credential-provider CRUDL", () => {
});

test("updates an OAuth2 credential provider", async () => {
const stdout = await run([
"identity",
"oauth2-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"updated-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
const stdout = await run(
[
"identity",
"oauth2-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"updated-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
"-",
],
"updated-secret",
]);
);

matchGolden(FIXTURES, "update.golden.json", stdout);
expect(JSON.parse(stdout).name).toBe(FIXTURE_PROVIDER_NAME);
Expand Down
23 changes: 21 additions & 2 deletions src/handlers/identity/oauth2-credential-provider/oauth2.test.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -67,8 +67,9 @@ const UPDATE_RESPONSE = {
async function run(
args: string[],
core = new TestCoreClient(),
stdin?: string,
): Promise<{ core: TestCoreClient; stdout: string }> {
const io = testIO();
const io = testIO({ stdin });
const root = createRootHandler(core, {
io: io.io,
logger: createSilentLogger(),
Expand DownExpand Up@@ -287,6 +288,23 @@ describe("oauth2-credential-provider flag validation", () => {
],
/requires one of --discovery-url or --authorization-server-metadata/,
],
[
"create: --client-secret with an inline value",
[
"identity",
"oauth2-credential-provider",
"create",
"--name",
"x",
"--vendor",
"CustomOauth2",
"--discovery-url",
"https://example.com",
"--client-secret",
"s-inline",
],
/file:\/\//,
],
] as const)("enforces vendor/config-mode rules for `%s`", async (_label, args, message) => {
expect(run([...args])).rejects.toThrow(message);
});
Expand DownExpand Up@@ -477,9 +495,10 @@ describe("OAuth2 update handler", () => {
PROVIDER_NAME,
...vendorArgs,
"--client-secret",
"updated-secret",
"-",
],
core,
"updated-secret",
);

const updateCall = core.identity.calls[1];
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -45,11 +45,9 @@ export const createUpdateOauth2CredentialProviderHandler = (core: Core, io: AppI
flag("vendor", "the OAuth2 vendor", z.string().optional()),
flag(
"client-secret",
"the client secret (inline, file://path, or -)",
"the client secret (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{
sensitive: true,
},
{ sensitive: true },
),
flag(
"client-secret-reference",
Expand DownExpand Up@@ -131,7 +129,7 @@ export const createUpdateOauth2CredentialProviderHandler = (core: Core, io: AppI
validateCompleteConfigKey(providerConfigMode, existing.oauth2ProviderConfigOutput);

const resolver = new SourceResolver({ stdin: io.stdin });
const clientSecret = await resolver.resolveText("client-secret", flags["client-secret"]);
const clientSecret = await resolver.resolveSecret("client-secret", flags["client-secret"]);

const clientSecretConfig = hasSecretRef
? parseSecretReference("client-secret-reference", flags["client-secret-reference"]!)
Expand Down
4 changes: 4 additions & 0 deletions src/handlers/project/add/runtime/index.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -325,6 +325,10 @@ describe("project add runtime", () => {
"--api-key is only available on template path",
["--name", "my_agent", ...byo, "--api-key", "-"],
],
[
"--api-key rejects an inline secret value",
["--name", "my_agent", ...template, "--api-key", "sk-inline"],
],
[
"invalid memory JSON schema",
["--name", "my_agent", ...template, "--memory", '{"mode":"invalid"}'],
Expand Down
2 changes: 1 addition & 1 deletion src/handlers/project/add/runtime/index.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -151,7 +151,7 @@ export const createAddRuntimeHandler = (config: AddProjectResourceConfig) =>
const entrypoint = flags.entrypoint ?? "main.py";

const source = new SourceResolver({ stdin: config.io.stdin });
const apiKey = await source.resolveText("api-key", flags["api-key"]);
const apiKey = await source.resolveSecret("api-key", flags["api-key"]);

if (flags["custom-docker-build-args"] && !flags.dockerfile && !flags["build-context-path"])
throw new InputValidationError(
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,9 +14,12 @@ export const createCreateApiKeyCredentialProviderHandler = (core: Core, io: AppI
description: "create an API key credential provider",
flags: [
flag("name", "the name of the API key credential provider", z.string().optional()),
flag("api-key", "the API key value (inline, file://path, or -)", z.string().optional(), {
sensitive: true,
}),
flag(
"api-key",
"the API key (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{ sensitive: true },
),
flag(
"api-key-secret-reference",
'external secret reference JSON: {"secretId":"<arn>","jsonKey":"<key>"}',
Expand DownExpand Up@@ -44,7 +47,7 @@ export const createCreateApiKeyCredentialProviderHandler = (core: Core, io: AppI
}

const resolver = new SourceResolver({ stdin: io.stdin });
const apiKey = await resolver.resolveText("api-key", flags["api-key"]);
const apiKey = await resolver.resolveSecret("api-key", flags["api-key"]);
const apiKeySecretConfig = hasSecretRef
? parseSecretReference("api-key-secret-reference", flags["api-key-secret-reference"]!)
: undefined;
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,9 +14,12 @@ export const createUpdateApiKeyCredentialProviderHandler = (core: Core, io: AppI
description: "update an API key credential provider",
flags: [
flag("name", "the name of the API key credential provider", z.string().optional()),
flag("api-key", "the new API key value (inline, file://path, or -)", z.string().optional(), {
sensitive: true,
}),
flag(
"api-key",
"the new API key (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{ sensitive: true },
),
flag(
"api-key-secret-reference",
'external secret reference JSON: {"secretId":"<arn>","jsonKey":"<key>"}',
Expand DownExpand Up@@ -57,7 +60,7 @@ export const createUpdateApiKeyCredentialProviderHandler = (core: Core, io: AppI
}

const resolver = new SourceResolver({ stdin: io.stdin });
const apiKey = await resolver.resolveText("api-key", flags["api-key"]);
const apiKey = await resolver.resolveSecret("api-key", flags["api-key"]);
const apiKeySecretConfig = hasSecretRef
? parseSecretReference("api-key-secret-reference", flags["api-key-secret-reference"]!)
: undefined;
Expand Down
74 changes: 48 additions & 26 deletions src/handlers/identity/identity.test.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,8 +32,8 @@ function createFixtureCore(): CoreClient {
});
}

async function run(args: string[]): Promise<string> {
const io = testIO();
async function run(args: string[], stdin?: string): Promise<string> {
const io = testIO({ stdin });
const root = createRootHandler(createFixtureCore(), {
io: io.io,
logger: createSilentLogger(),
Expand DownExpand Up@@ -101,29 +101,35 @@ describe("api-key-credential-provider TUI dispatch", () => {

describe("api-key-credential-provider CRUDL", () => {
test("creates an API key credential provider", async () => {
const stdout = await run([
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
const stdout = await run(
[
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
"-",
],
"test-api-key-value",
]);
);

matchGolden(FIXTURES, "create.golden.json", stdout);
});

test("creates a second API key credential provider for pagination", async () => {
const stdout = await run([
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--api-key",
const stdout = await run(
[
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--api-key",
"-",
],
"test-api-key-value-2",
]);
);

matchGolden(FIXTURES, "create-2.golden.json", stdout);
});
Expand DownExpand Up@@ -176,15 +182,18 @@ describe("api-key-credential-provider CRUDL", () => {
});

test("updates an API key credential provider", async () => {
const stdout = await run([
"identity",
"api-key-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
const stdout = await run(
[
"identity",
"api-key-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
"-",
],
"updated-api-key-value",
]);
);

matchGolden(FIXTURES, "update.golden.json", stdout);
expect(JSON.parse(stdout).name).toBe(FIXTURE_PROVIDER_NAME);
Expand DownExpand Up@@ -301,6 +310,19 @@ describe("api-key-credential-provider CRUDL", () => {
],
/mutually exclusive/,
],
[
"create: --api-key with an inline value",
[
"identity",
"api-key-credential-provider",
"create",
"--name",
"x",
"--api-key",
"sk-inline",
],
/file:\/\//,
],
] as const)("rejects invalid secret input for `%s`", async (_label, args, message) => {
expect(run([...args])).rejects.toThrow(message);
});
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -23,11 +23,9 @@ export const createCreateOauth2CredentialProviderHandler = (core: Core, io: AppI
flag("vendor", "the OAuth2 vendor (e.g. CustomOauth2, GithubOauth2)", z.string().optional()),
flag(
"client-secret",
"the client secret (inline, file://path, or -)",
"the client secret (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{
sensitive: true,
},
{ sensitive: true },
),
flag(
"client-secret-reference",
Expand DownExpand Up@@ -81,7 +79,7 @@ export const createCreateOauth2CredentialProviderHandler = (core: Core, io: AppI
validateProviderConfigMode(providerConfigMode, vendor);

const resolver = new SourceResolver({ stdin: io.stdin });
const clientSecret = await resolver.resolveText("client-secret", flags["client-secret"]);
const clientSecret = await resolver.resolveSecret("client-secret", flags["client-secret"]);

const clientSecretConfig = hasSecretRef
? parseSecretReference("client-secret-reference", flags["client-secret-reference"]!)
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,8 +32,8 @@ function createFixtureCore(): CoreClient {
});
}

async function run(args: string[]): Promise<string> {
const io = testIO();
async function run(args: string[], stdin?: string): Promise<string> {
const io = testIO({ stdin });
const root = createRootHandler(createFixtureCore(), {
io: io.io,
logger: createSilentLogger(),
Expand All@@ -46,41 +46,47 @@ async function run(args: string[]): Promise<string> {

describe("oauth2-credential-provider CRUDL", () => {
test("creates an OAuth2 credential provider", async () => {
const stdout = await run([
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
const stdout = await run(
[
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
"-",
],
"fixture-secret",
]);
);

matchGolden(FIXTURES, "create.golden.json", stdout);
});

test("creates a second OAuth2 credential provider for pagination", async () => {
const stdout = await run([
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id-2",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
const stdout = await run(
[
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id-2",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
"-",
],
"fixture-secret-2",
]);
);

matchGolden(FIXTURES, "create-2.golden.json", stdout);
});
Expand DownExpand Up@@ -133,21 +139,24 @@ describe("oauth2-credential-provider CRUDL", () => {
});

test("updates an OAuth2 credential provider", async () => {
const stdout = await run([
"identity",
"oauth2-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"updated-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
const stdout = await run(
[
"identity",
"oauth2-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"updated-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
"-",
],
"updated-secret",
]);
);

matchGolden(FIXTURES, "update.golden.json", stdout);
expect(JSON.parse(stdout).name).toBe(FIXTURE_PROVIDER_NAME);
Expand Down
23 changes: 21 additions & 2 deletions src/handlers/identity/oauth2-credential-provider/oauth2.test.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -67,8 +67,9 @@ const UPDATE_RESPONSE = {
async function run(
args: string[],
core = new TestCoreClient(),
stdin?: string,
): Promise<{ core: TestCoreClient; stdout: string }> {
const io = testIO();
const io = testIO({ stdin });
const root = createRootHandler(core, {
io: io.io,
logger: createSilentLogger(),
Expand DownExpand Up@@ -287,6 +288,23 @@ describe("oauth2-credential-provider flag validation", () => {
],
/requires one of --discovery-url or --authorization-server-metadata/,
],
[
"create: --client-secret with an inline value",
[
"identity",
"oauth2-credential-provider",
"create",
"--name",
"x",
"--vendor",
"CustomOauth2",
"--discovery-url",
"https://example.com",
"--client-secret",
"s-inline",
],
/file:\/\//,
],
] as const)("enforces vendor/config-mode rules for `%s`", async (_label, args, message) => {
expect(run([...args])).rejects.toThrow(message);
});
Expand DownExpand Up@@ -477,9 +495,10 @@ describe("OAuth2 update handler", () => {
PROVIDER_NAME,
...vendorArgs,
"--client-secret",
"updated-secret",
"-",
],
core,
"updated-secret",
);

const updateCall = core.identity.calls[1];
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -45,11 +45,9 @@ export const createUpdateOauth2CredentialProviderHandler = (core: Core, io: AppI
flag("vendor", "the OAuth2 vendor", z.string().optional()),
flag(
"client-secret",
"the client secret (inline, file://path, or -)",
"the client secret (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{
sensitive: true,
},
{ sensitive: true },
),
flag(
"client-secret-reference",
Expand DownExpand Up@@ -131,7 +129,7 @@ export const createUpdateOauth2CredentialProviderHandler = (core: Core, io: AppI
validateCompleteConfigKey(providerConfigMode, existing.oauth2ProviderConfigOutput);

const resolver = new SourceResolver({ stdin: io.stdin });
const clientSecret = await resolver.resolveText("client-secret", flags["client-secret"]);
const clientSecret = await resolver.resolveSecret("client-secret", flags["client-secret"]);

const clientSecretConfig = hasSecretRef
? parseSecretReference("client-secret-reference", flags["client-secret-reference"]!)
Expand Down
4 changes: 4 additions & 0 deletions src/handlers/project/add/runtime/index.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -325,6 +325,10 @@ describe("project add runtime", () => {
"--api-key is only available on template path",
["--name", "my_agent", ...byo, "--api-key", "-"],
],
[
"--api-key rejects an inline secret value",
["--name", "my_agent", ...template, "--api-key", "sk-inline"],
],
[
"invalid memory JSON schema",
["--name", "my_agent", ...template, "--memory", '{"mode":"invalid"}'],
Expand Down
2 changes: 1 addition & 1 deletion src/handlers/project/add/runtime/index.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -151,7 +151,7 @@ export const createAddRuntimeHandler = (config: AddProjectResourceConfig) =>
const entrypoint = flags.entrypoint ?? "main.py";

const source = new SourceResolver({ stdin: config.io.stdin });
const apiKey = await source.resolveText("api-key", flags["api-key"]);
const apiKey = await source.resolveSecret("api-key", flags["api-key"]);

if (flags["custom-docker-build-args"] && !flags.dockerfile && !flags["build-context-path"])
throw new InputValidationError(
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,9 +14,12 @@ export const createCreateApiKeyCredentialProviderHandler = (core: Core, io: AppI
description: "create an API key credential provider",
flags: [
flag("name", "the name of the API key credential provider", z.string().optional()),
flag("api-key", "the API key value (inline, file://path, or -)", z.string().optional(), {
sensitive: true,
}),
flag(
"api-key",
"the API key (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{ sensitive: true },
),
flag(
"api-key-secret-reference",
'external secret reference JSON: {"secretId":"<arn>","jsonKey":"<key>"}',
Expand DownExpand Up@@ -44,7 +47,7 @@ export const createCreateApiKeyCredentialProviderHandler = (core: Core, io: AppI
}

const resolver = new SourceResolver({ stdin: io.stdin });
const apiKey = await resolver.resolveText("api-key", flags["api-key"]);
const apiKey = await resolver.resolveSecret("api-key", flags["api-key"]);
const apiKeySecretConfig = hasSecretRef
? parseSecretReference("api-key-secret-reference", flags["api-key-secret-reference"]!)
: undefined;
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,9 +14,12 @@ export const createUpdateApiKeyCredentialProviderHandler = (core: Core, io: AppI
description: "update an API key credential provider",
flags: [
flag("name", "the name of the API key credential provider", z.string().optional()),
flag("api-key", "the new API key value (inline, file://path, or -)", z.string().optional(), {
sensitive: true,
}),
flag(
"api-key",
"the new API key (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{ sensitive: true },
),
flag(
"api-key-secret-reference",
'external secret reference JSON: {"secretId":"<arn>","jsonKey":"<key>"}',
Expand DownExpand Up@@ -57,7 +60,7 @@ export const createUpdateApiKeyCredentialProviderHandler = (core: Core, io: AppI
}

const resolver = new SourceResolver({ stdin: io.stdin });
const apiKey = await resolver.resolveText("api-key", flags["api-key"]);
const apiKey = await resolver.resolveSecret("api-key", flags["api-key"]);
const apiKeySecretConfig = hasSecretRef
? parseSecretReference("api-key-secret-reference", flags["api-key-secret-reference"]!)
: undefined;
Expand Down
74 changes: 48 additions & 26 deletions src/handlers/identity/identity.test.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,8 +32,8 @@ function createFixtureCore(): CoreClient {
});
}

async function run(args: string[]): Promise<string> {
const io = testIO();
async function run(args: string[], stdin?: string): Promise<string> {
const io = testIO({ stdin });
const root = createRootHandler(createFixtureCore(), {
io: io.io,
logger: createSilentLogger(),
Expand DownExpand Up@@ -101,29 +101,35 @@ describe("api-key-credential-provider TUI dispatch", () => {

describe("api-key-credential-provider CRUDL", () => {
test("creates an API key credential provider", async () => {
const stdout = await run([
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
const stdout = await run(
[
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
"-",
],
"test-api-key-value",
]);
);

matchGolden(FIXTURES, "create.golden.json", stdout);
});

test("creates a second API key credential provider for pagination", async () => {
const stdout = await run([
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--api-key",
const stdout = await run(
[
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--api-key",
"-",
],
"test-api-key-value-2",
]);
);

matchGolden(FIXTURES, "create-2.golden.json", stdout);
});
Expand DownExpand Up@@ -176,15 +182,18 @@ describe("api-key-credential-provider CRUDL", () => {
});

test("updates an API key credential provider", async () => {
const stdout = await run([
"identity",
"api-key-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
const stdout = await run(
[
"identity",
"api-key-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
"-",
],
"updated-api-key-value",
]);
);

matchGolden(FIXTURES, "update.golden.json", stdout);
expect(JSON.parse(stdout).name).toBe(FIXTURE_PROVIDER_NAME);
Expand DownExpand Up@@ -301,6 +310,19 @@ describe("api-key-credential-provider CRUDL", () => {
],
/mutually exclusive/,
],
[
"create: --api-key with an inline value",
[
"identity",
"api-key-credential-provider",
"create",
"--name",
"x",
"--api-key",
"sk-inline",
],
/file:\/\//,
],
] as const)("rejects invalid secret input for `%s`", async (_label, args, message) => {
expect(run([...args])).rejects.toThrow(message);
});
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -23,11 +23,9 @@ export const createCreateOauth2CredentialProviderHandler = (core: Core, io: AppI
flag("vendor", "the OAuth2 vendor (e.g. CustomOauth2, GithubOauth2)", z.string().optional()),
flag(
"client-secret",
"the client secret (inline, file://path, or -)",
"the client secret (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{
sensitive: true,
},
{ sensitive: true },
),
flag(
"client-secret-reference",
Expand DownExpand Up@@ -81,7 +79,7 @@ export const createCreateOauth2CredentialProviderHandler = (core: Core, io: AppI
validateProviderConfigMode(providerConfigMode, vendor);

const resolver = new SourceResolver({ stdin: io.stdin });
const clientSecret = await resolver.resolveText("client-secret", flags["client-secret"]);
const clientSecret = await resolver.resolveSecret("client-secret", flags["client-secret"]);

const clientSecretConfig = hasSecretRef
? parseSecretReference("client-secret-reference", flags["client-secret-reference"]!)
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,8 +32,8 @@ function createFixtureCore(): CoreClient {
});
}

async function run(args: string[]): Promise<string> {
const io = testIO();
async function run(args: string[], stdin?: string): Promise<string> {
const io = testIO({ stdin });
const root = createRootHandler(createFixtureCore(), {
io: io.io,
logger: createSilentLogger(),
Expand All@@ -46,41 +46,47 @@ async function run(args: string[]): Promise<string> {

describe("oauth2-credential-provider CRUDL", () => {
test("creates an OAuth2 credential provider", async () => {
const stdout = await run([
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
const stdout = await run(
[
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
"-",
],
"fixture-secret",
]);
);

matchGolden(FIXTURES, "create.golden.json", stdout);
});

test("creates a second OAuth2 credential provider for pagination", async () => {
const stdout = await run([
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id-2",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
const stdout = await run(
[
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id-2",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
"-",
],
"fixture-secret-2",
]);
);

matchGolden(FIXTURES, "create-2.golden.json", stdout);
});
Expand DownExpand Up@@ -133,21 +139,24 @@ describe("oauth2-credential-provider CRUDL", () => {
});

test("updates an OAuth2 credential provider", async () => {
const stdout = await run([
"identity",
"oauth2-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"updated-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
const stdout = await run(
[
"identity",
"oauth2-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"updated-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
"-",
],
"updated-secret",
]);
);

matchGolden(FIXTURES, "update.golden.json", stdout);
expect(JSON.parse(stdout).name).toBe(FIXTURE_PROVIDER_NAME);
Expand Down
23 changes: 21 additions & 2 deletions src/handlers/identity/oauth2-credential-provider/oauth2.test.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -67,8 +67,9 @@ const UPDATE_RESPONSE = {
async function run(
args: string[],
core = new TestCoreClient(),
stdin?: string,
): Promise<{ core: TestCoreClient; stdout: string }> {
const io = testIO();
const io = testIO({ stdin });
const root = createRootHandler(core, {
io: io.io,
logger: createSilentLogger(),
Expand DownExpand Up@@ -287,6 +288,23 @@ describe("oauth2-credential-provider flag validation", () => {
],
/requires one of --discovery-url or --authorization-server-metadata/,
],
[
"create: --client-secret with an inline value",
[
"identity",
"oauth2-credential-provider",
"create",
"--name",
"x",
"--vendor",
"CustomOauth2",
"--discovery-url",
"https://example.com",
"--client-secret",
"s-inline",
],
/file:\/\//,
],
] as const)("enforces vendor/config-mode rules for `%s`", async (_label, args, message) => {
expect(run([...args])).rejects.toThrow(message);
});
Expand DownExpand Up@@ -477,9 +495,10 @@ describe("OAuth2 update handler", () => {
PROVIDER_NAME,
...vendorArgs,
"--client-secret",
"updated-secret",
"-",
],
core,
"updated-secret",
);

const updateCall = core.identity.calls[1];
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -45,11 +45,9 @@ export const createUpdateOauth2CredentialProviderHandler = (core: Core, io: AppI
flag("vendor", "the OAuth2 vendor", z.string().optional()),
flag(
"client-secret",
"the client secret (inline, file://path, or -)",
"the client secret (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{
sensitive: true,
},
{ sensitive: true },
),
flag(
"client-secret-reference",
Expand DownExpand Up@@ -131,7 +129,7 @@ export const createUpdateOauth2CredentialProviderHandler = (core: Core, io: AppI
validateCompleteConfigKey(providerConfigMode, existing.oauth2ProviderConfigOutput);

const resolver = new SourceResolver({ stdin: io.stdin });
const clientSecret = await resolver.resolveText("client-secret", flags["client-secret"]);
const clientSecret = await resolver.resolveSecret("client-secret", flags["client-secret"]);

const clientSecretConfig = hasSecretRef
? parseSecretReference("client-secret-reference", flags["client-secret-reference"]!)
Expand Down
4 changes: 4 additions & 0 deletions src/handlers/project/add/runtime/index.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -325,6 +325,10 @@ describe("project add runtime", () => {
"--api-key is only available on template path",
["--name", "my_agent", ...byo, "--api-key", "-"],
],
[
"--api-key rejects an inline secret value",
["--name", "my_agent", ...template, "--api-key", "sk-inline"],
],
[
"invalid memory JSON schema",
["--name", "my_agent", ...template, "--memory", '{"mode":"invalid"}'],
Expand Down
2 changes: 1 addition & 1 deletion src/handlers/project/add/runtime/index.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -151,7 +151,7 @@ export const createAddRuntimeHandler = (config: AddProjectResourceConfig) =>
const entrypoint = flags.entrypoint ?? "main.py";

const source = new SourceResolver({ stdin: config.io.stdin });
const apiKey = await source.resolveText("api-key", flags["api-key"]);
const apiKey = await source.resolveSecret("api-key", flags["api-key"]);

if (flags["custom-docker-build-args"] && !flags.dockerfile && !flags["build-context-path"])
throw new InputValidationError(
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,9 +14,12 @@ export const createCreateApiKeyCredentialProviderHandler = (core: Core, io: AppI
description: "create an API key credential provider",
flags: [
flag("name", "the name of the API key credential provider", z.string().optional()),
flag("api-key", "the API key value (inline, file://path, or -)", z.string().optional(), {
sensitive: true,
}),
flag(
"api-key",
"the API key (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{ sensitive: true },
),
flag(
"api-key-secret-reference",
'external secret reference JSON: {"secretId":"<arn>","jsonKey":"<key>"}',
Expand DownExpand Up@@ -44,7 +47,7 @@ export const createCreateApiKeyCredentialProviderHandler = (core: Core, io: AppI
}

const resolver = new SourceResolver({ stdin: io.stdin });
const apiKey = await resolver.resolveText("api-key", flags["api-key"]);
const apiKey = await resolver.resolveSecret("api-key", flags["api-key"]);
const apiKeySecretConfig = hasSecretRef
? parseSecretReference("api-key-secret-reference", flags["api-key-secret-reference"]!)
: undefined;
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,9 +14,12 @@ export const createUpdateApiKeyCredentialProviderHandler = (core: Core, io: AppI
description: "update an API key credential provider",
flags: [
flag("name", "the name of the API key credential provider", z.string().optional()),
flag("api-key", "the new API key value (inline, file://path, or -)", z.string().optional(), {
sensitive: true,
}),
flag(
"api-key",
"the new API key (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{ sensitive: true },
),
flag(
"api-key-secret-reference",
'external secret reference JSON: {"secretId":"<arn>","jsonKey":"<key>"}',
Expand DownExpand Up@@ -57,7 +60,7 @@ export const createUpdateApiKeyCredentialProviderHandler = (core: Core, io: AppI
}

const resolver = new SourceResolver({ stdin: io.stdin });
const apiKey = await resolver.resolveText("api-key", flags["api-key"]);
const apiKey = await resolver.resolveSecret("api-key", flags["api-key"]);
const apiKeySecretConfig = hasSecretRef
? parseSecretReference("api-key-secret-reference", flags["api-key-secret-reference"]!)
: undefined;
Expand Down
74 changes: 48 additions & 26 deletions src/handlers/identity/identity.test.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,8 +32,8 @@ function createFixtureCore(): CoreClient {
});
}

async function run(args: string[]): Promise<string> {
const io = testIO();
async function run(args: string[], stdin?: string): Promise<string> {
const io = testIO({ stdin });
const root = createRootHandler(createFixtureCore(), {
io: io.io,
logger: createSilentLogger(),
Expand DownExpand Up@@ -101,29 +101,35 @@ describe("api-key-credential-provider TUI dispatch", () => {

describe("api-key-credential-provider CRUDL", () => {
test("creates an API key credential provider", async () => {
const stdout = await run([
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
const stdout = await run(
[
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
"-",
],
"test-api-key-value",
]);
);

matchGolden(FIXTURES, "create.golden.json", stdout);
});

test("creates a second API key credential provider for pagination", async () => {
const stdout = await run([
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--api-key",
const stdout = await run(
[
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--api-key",
"-",
],
"test-api-key-value-2",
]);
);

matchGolden(FIXTURES, "create-2.golden.json", stdout);
});
Expand DownExpand Up@@ -176,15 +182,18 @@ describe("api-key-credential-provider CRUDL", () => {
});

test("updates an API key credential provider", async () => {
const stdout = await run([
"identity",
"api-key-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
const stdout = await run(
[
"identity",
"api-key-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
"-",
],
"updated-api-key-value",
]);
);

matchGolden(FIXTURES, "update.golden.json", stdout);
expect(JSON.parse(stdout).name).toBe(FIXTURE_PROVIDER_NAME);
Expand DownExpand Up@@ -301,6 +310,19 @@ describe("api-key-credential-provider CRUDL", () => {
],
/mutually exclusive/,
],
[
"create: --api-key with an inline value",
[
"identity",
"api-key-credential-provider",
"create",
"--name",
"x",
"--api-key",
"sk-inline",
],
/file:\/\//,
],
] as const)("rejects invalid secret input for `%s`", async (_label, args, message) => {
expect(run([...args])).rejects.toThrow(message);
});
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -23,11 +23,9 @@ export const createCreateOauth2CredentialProviderHandler = (core: Core, io: AppI
flag("vendor", "the OAuth2 vendor (e.g. CustomOauth2, GithubOauth2)", z.string().optional()),
flag(
"client-secret",
"the client secret (inline, file://path, or -)",
"the client secret (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{
sensitive: true,
},
{ sensitive: true },
),
flag(
"client-secret-reference",
Expand DownExpand Up@@ -81,7 +79,7 @@ export const createCreateOauth2CredentialProviderHandler = (core: Core, io: AppI
validateProviderConfigMode(providerConfigMode, vendor);

const resolver = new SourceResolver({ stdin: io.stdin });
const clientSecret = await resolver.resolveText("client-secret", flags["client-secret"]);
const clientSecret = await resolver.resolveSecret("client-secret", flags["client-secret"]);

const clientSecretConfig = hasSecretRef
? parseSecretReference("client-secret-reference", flags["client-secret-reference"]!)
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,8 +32,8 @@ function createFixtureCore(): CoreClient {
});
}

async function run(args: string[]): Promise<string> {
const io = testIO();
async function run(args: string[], stdin?: string): Promise<string> {
const io = testIO({ stdin });
const root = createRootHandler(createFixtureCore(), {
io: io.io,
logger: createSilentLogger(),
Expand All@@ -46,41 +46,47 @@ async function run(args: string[]): Promise<string> {

describe("oauth2-credential-provider CRUDL", () => {
test("creates an OAuth2 credential provider", async () => {
const stdout = await run([
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
const stdout = await run(
[
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
"-",
],
"fixture-secret",
]);
);

matchGolden(FIXTURES, "create.golden.json", stdout);
});

test("creates a second OAuth2 credential provider for pagination", async () => {
const stdout = await run([
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id-2",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
const stdout = await run(
[
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id-2",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
"-",
],
"fixture-secret-2",
]);
);

matchGolden(FIXTURES, "create-2.golden.json", stdout);
});
Expand DownExpand Up@@ -133,21 +139,24 @@ describe("oauth2-credential-provider CRUDL", () => {
});

test("updates an OAuth2 credential provider", async () => {
const stdout = await run([
"identity",
"oauth2-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"updated-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
const stdout = await run(
[
"identity",
"oauth2-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"updated-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
"-",
],
"updated-secret",
]);
);

matchGolden(FIXTURES, "update.golden.json", stdout);
expect(JSON.parse(stdout).name).toBe(FIXTURE_PROVIDER_NAME);
Expand Down
23 changes: 21 additions & 2 deletions src/handlers/identity/oauth2-credential-provider/oauth2.test.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -67,8 +67,9 @@ const UPDATE_RESPONSE = {
async function run(
args: string[],
core = new TestCoreClient(),
stdin?: string,
): Promise<{ core: TestCoreClient; stdout: string }> {
const io = testIO();
const io = testIO({ stdin });
const root = createRootHandler(core, {
io: io.io,
logger: createSilentLogger(),
Expand DownExpand Up@@ -287,6 +288,23 @@ describe("oauth2-credential-provider flag validation", () => {
],
/requires one of --discovery-url or --authorization-server-metadata/,
],
[
"create: --client-secret with an inline value",
[
"identity",
"oauth2-credential-provider",
"create",
"--name",
"x",
"--vendor",
"CustomOauth2",
"--discovery-url",
"https://example.com",
"--client-secret",
"s-inline",
],
/file:\/\//,
],
] as const)("enforces vendor/config-mode rules for `%s`", async (_label, args, message) => {
expect(run([...args])).rejects.toThrow(message);
});
Expand DownExpand Up@@ -477,9 +495,10 @@ describe("OAuth2 update handler", () => {
PROVIDER_NAME,
...vendorArgs,
"--client-secret",
"updated-secret",
"-",
],
core,
"updated-secret",
);

const updateCall = core.identity.calls[1];
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -45,11 +45,9 @@ export const createUpdateOauth2CredentialProviderHandler = (core: Core, io: AppI
flag("vendor", "the OAuth2 vendor", z.string().optional()),
flag(
"client-secret",
"the client secret (inline, file://path, or -)",
"the client secret (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{
sensitive: true,
},
{ sensitive: true },
),
flag(
"client-secret-reference",
Expand DownExpand Up@@ -131,7 +129,7 @@ export const createUpdateOauth2CredentialProviderHandler = (core: Core, io: AppI
validateCompleteConfigKey(providerConfigMode, existing.oauth2ProviderConfigOutput);

const resolver = new SourceResolver({ stdin: io.stdin });
const clientSecret = await resolver.resolveText("client-secret", flags["client-secret"]);
const clientSecret = await resolver.resolveSecret("client-secret", flags["client-secret"]);

const clientSecretConfig = hasSecretRef
? parseSecretReference("client-secret-reference", flags["client-secret-reference"]!)
Expand Down
4 changes: 4 additions & 0 deletions src/handlers/project/add/runtime/index.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -325,6 +325,10 @@ describe("project add runtime", () => {
"--api-key is only available on template path",
["--name", "my_agent", ...byo, "--api-key", "-"],
],
[
"--api-key rejects an inline secret value",
["--name", "my_agent", ...template, "--api-key", "sk-inline"],
],
[
"invalid memory JSON schema",
["--name", "my_agent", ...template, "--memory", '{"mode":"invalid"}'],
Expand Down
2 changes: 1 addition & 1 deletion src/handlers/project/add/runtime/index.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -151,7 +151,7 @@ export const createAddRuntimeHandler = (config: AddProjectResourceConfig) =>
const entrypoint = flags.entrypoint ?? "main.py";

const source = new SourceResolver({ stdin: config.io.stdin });
const apiKey = await source.resolveText("api-key", flags["api-key"]);
const apiKey = await source.resolveSecret("api-key", flags["api-key"]);

if (flags["custom-docker-build-args"] && !flags.dockerfile && !flags["build-context-path"])
throw new InputValidationError(
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,9 +14,12 @@ export const createCreateApiKeyCredentialProviderHandler = (core: Core, io: AppI
description: "create an API key credential provider",
flags: [
flag("name", "the name of the API key credential provider", z.string().optional()),
flag("api-key", "the API key value (inline, file://path, or -)", z.string().optional(), {
sensitive: true,
}),
flag(
"api-key",
"the API key (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{ sensitive: true },
),
flag(
"api-key-secret-reference",
'external secret reference JSON: {"secretId":"<arn>","jsonKey":"<key>"}',
Expand DownExpand Up@@ -44,7 +47,7 @@ export const createCreateApiKeyCredentialProviderHandler = (core: Core, io: AppI
}

const resolver = new SourceResolver({ stdin: io.stdin });
const apiKey = await resolver.resolveText("api-key", flags["api-key"]);
const apiKey = await resolver.resolveSecret("api-key", flags["api-key"]);
const apiKeySecretConfig = hasSecretRef
? parseSecretReference("api-key-secret-reference", flags["api-key-secret-reference"]!)
: undefined;
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,9 +14,12 @@ export const createUpdateApiKeyCredentialProviderHandler = (core: Core, io: AppI
description: "update an API key credential provider",
flags: [
flag("name", "the name of the API key credential provider", z.string().optional()),
flag("api-key", "the new API key value (inline, file://path, or -)", z.string().optional(), {
sensitive: true,
}),
flag(
"api-key",
"the new API key (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{ sensitive: true },
),
flag(
"api-key-secret-reference",
'external secret reference JSON: {"secretId":"<arn>","jsonKey":"<key>"}',
Expand DownExpand Up@@ -57,7 +60,7 @@ export const createUpdateApiKeyCredentialProviderHandler = (core: Core, io: AppI
}

const resolver = new SourceResolver({ stdin: io.stdin });
const apiKey = await resolver.resolveText("api-key", flags["api-key"]);
const apiKey = await resolver.resolveSecret("api-key", flags["api-key"]);
const apiKeySecretConfig = hasSecretRef
? parseSecretReference("api-key-secret-reference", flags["api-key-secret-reference"]!)
: undefined;
Expand Down
74 changes: 48 additions & 26 deletions src/handlers/identity/identity.test.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,8 +32,8 @@ function createFixtureCore(): CoreClient {
});
}

async function run(args: string[]): Promise<string> {
const io = testIO();
async function run(args: string[], stdin?: string): Promise<string> {
const io = testIO({ stdin });
const root = createRootHandler(createFixtureCore(), {
io: io.io,
logger: createSilentLogger(),
Expand DownExpand Up@@ -101,29 +101,35 @@ describe("api-key-credential-provider TUI dispatch", () => {

describe("api-key-credential-provider CRUDL", () => {
test("creates an API key credential provider", async () => {
const stdout = await run([
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
const stdout = await run(
[
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
"-",
],
"test-api-key-value",
]);
);

matchGolden(FIXTURES, "create.golden.json", stdout);
});

test("creates a second API key credential provider for pagination", async () => {
const stdout = await run([
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--api-key",
const stdout = await run(
[
"identity",
"api-key-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--api-key",
"-",
],
"test-api-key-value-2",
]);
);

matchGolden(FIXTURES, "create-2.golden.json", stdout);
});
Expand DownExpand Up@@ -176,15 +182,18 @@ describe("api-key-credential-provider CRUDL", () => {
});

test("updates an API key credential provider", async () => {
const stdout = await run([
"identity",
"api-key-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
const stdout = await run(
[
"identity",
"api-key-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--api-key",
"-",
],
"updated-api-key-value",
]);
);

matchGolden(FIXTURES, "update.golden.json", stdout);
expect(JSON.parse(stdout).name).toBe(FIXTURE_PROVIDER_NAME);
Expand DownExpand Up@@ -301,6 +310,19 @@ describe("api-key-credential-provider CRUDL", () => {
],
/mutually exclusive/,
],
[
"create: --api-key with an inline value",
[
"identity",
"api-key-credential-provider",
"create",
"--name",
"x",
"--api-key",
"sk-inline",
],
/file:\/\//,
],
] as const)("rejects invalid secret input for `%s`", async (_label, args, message) => {
expect(run([...args])).rejects.toThrow(message);
});
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -23,11 +23,9 @@ export const createCreateOauth2CredentialProviderHandler = (core: Core, io: AppI
flag("vendor", "the OAuth2 vendor (e.g. CustomOauth2, GithubOauth2)", z.string().optional()),
flag(
"client-secret",
"the client secret (inline, file://path, or -)",
"the client secret (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{
sensitive: true,
},
{ sensitive: true },
),
flag(
"client-secret-reference",
Expand DownExpand Up@@ -81,7 +79,7 @@ export const createCreateOauth2CredentialProviderHandler = (core: Core, io: AppI
validateProviderConfigMode(providerConfigMode, vendor);

const resolver = new SourceResolver({ stdin: io.stdin });
const clientSecret = await resolver.resolveText("client-secret", flags["client-secret"]);
const clientSecret = await resolver.resolveSecret("client-secret", flags["client-secret"]);

const clientSecretConfig = hasSecretRef
? parseSecretReference("client-secret-reference", flags["client-secret-reference"]!)
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,8 +32,8 @@ function createFixtureCore(): CoreClient {
});
}

async function run(args: string[]): Promise<string> {
const io = testIO();
async function run(args: string[], stdin?: string): Promise<string> {
const io = testIO({ stdin });
const root = createRootHandler(createFixtureCore(), {
io: io.io,
logger: createSilentLogger(),
Expand All@@ -46,41 +46,47 @@ async function run(args: string[]): Promise<string> {

describe("oauth2-credential-provider CRUDL", () => {
test("creates an OAuth2 credential provider", async () => {
const stdout = await run([
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
const stdout = await run(
[
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
"-",
],
"fixture-secret",
]);
);

matchGolden(FIXTURES, "create.golden.json", stdout);
});

test("creates a second OAuth2 credential provider for pagination", async () => {
const stdout = await run([
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id-2",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
const stdout = await run(
[
"identity",
"oauth2-credential-provider",
"create",
"--name",
FIXTURE_PROVIDER_NAME_2,
"--vendor",
"CustomOauth2",
"--client-id",
"fixture-client-id-2",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
"-",
],
"fixture-secret-2",
]);
);

matchGolden(FIXTURES, "create-2.golden.json", stdout);
});
Expand DownExpand Up@@ -133,21 +139,24 @@ describe("oauth2-credential-provider CRUDL", () => {
});

test("updates an OAuth2 credential provider", async () => {
const stdout = await run([
"identity",
"oauth2-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"updated-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
const stdout = await run(
[
"identity",
"oauth2-credential-provider",
"update",
"--name",
FIXTURE_PROVIDER_NAME,
"--vendor",
"CustomOauth2",
"--client-id",
"updated-client-id",
"--discovery-url",
"https://example.com/.well-known/openid-configuration",
"--client-secret",
"-",
],
"updated-secret",
]);
);

matchGolden(FIXTURES, "update.golden.json", stdout);
expect(JSON.parse(stdout).name).toBe(FIXTURE_PROVIDER_NAME);
Expand Down
23 changes: 21 additions & 2 deletions src/handlers/identity/oauth2-credential-provider/oauth2.test.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -67,8 +67,9 @@ const UPDATE_RESPONSE = {
async function run(
args: string[],
core = new TestCoreClient(),
stdin?: string,
): Promise<{ core: TestCoreClient; stdout: string }> {
const io = testIO();
const io = testIO({ stdin });
const root = createRootHandler(core, {
io: io.io,
logger: createSilentLogger(),
Expand DownExpand Up@@ -287,6 +288,23 @@ describe("oauth2-credential-provider flag validation", () => {
],
/requires one of --discovery-url or --authorization-server-metadata/,
],
[
"create: --client-secret with an inline value",
[
"identity",
"oauth2-credential-provider",
"create",
"--name",
"x",
"--vendor",
"CustomOauth2",
"--discovery-url",
"https://example.com",
"--client-secret",
"s-inline",
],
/file:\/\//,
],
] as const)("enforces vendor/config-mode rules for `%s`", async (_label, args, message) => {
expect(run([...args])).rejects.toThrow(message);
});
Expand DownExpand Up@@ -477,9 +495,10 @@ describe("OAuth2 update handler", () => {
PROVIDER_NAME,
...vendorArgs,
"--client-secret",
"updated-secret",
"-",
],
core,
"updated-secret",
);

const updateCall = core.identity.calls[1];
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -45,11 +45,9 @@ export const createUpdateOauth2CredentialProviderHandler = (core: Core, io: AppI
flag("vendor", "the OAuth2 vendor", z.string().optional()),
flag(
"client-secret",
"the client secret (inline, file://path, or -)",
"the client secret (file://path or - for stdin; inline values are rejected)",
z.string().optional(),
{
sensitive: true,
},
{ sensitive: true },
),
flag(
"client-secret-reference",
Expand DownExpand Up@@ -131,7 +129,7 @@ export const createUpdateOauth2CredentialProviderHandler = (core: Core, io: AppI
validateCompleteConfigKey(providerConfigMode, existing.oauth2ProviderConfigOutput);

const resolver = new SourceResolver({ stdin: io.stdin });
const clientSecret = await resolver.resolveText("client-secret", flags["client-secret"]);
const clientSecret = await resolver.resolveSecret("client-secret", flags["client-secret"]);

const clientSecretConfig = hasSecretRef
? parseSecretReference("client-secret-reference", flags["client-secret-reference"]!)
Expand Down
4 changes: 4 additions & 0 deletions src/handlers/project/add/runtime/index.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -325,6 +325,10 @@ describe("project add runtime", () => {
"--api-key is only available on template path",
["--name", "my_agent", ...byo, "--api-key", "-"],
],
[
"--api-key rejects an inline secret value",
["--name", "my_agent", ...template, "--api-key", "sk-inline"],
],
[
"invalid memory JSON schema",
["--name", "my_agent", ...template, "--memory", '{"mode":"invalid"}'],
Expand Down
2 changes: 1 addition & 1 deletion src/handlers/project/add/runtime/index.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -151,7 +151,7 @@ export const createAddRuntimeHandler = (config: AddProjectResourceConfig) =>
const entrypoint = flags.entrypoint ?? "main.py";

const source = new SourceResolver({ stdin: config.io.stdin });
const apiKey = await source.resolveText("api-key", flags["api-key"]);
const apiKey = await source.resolveSecret("api-key", flags["api-key"]);

if (flags["custom-docker-build-args"] && !flags.dockerfile && !flags["build-context-path"])
throw new InputValidationError(
Expand Down
Loading