Skip to content

fix(input-json): only read stdin with explicit --input-json - - #341

Merged
rafa-thayto merged 2 commits into
mainfrom
fix/input-json-explicit-stdin
Jun 30, 2026
Merged

fix(input-json): only read stdin with explicit --input-json -#341
rafa-thayto merged 2 commits into
mainfrom
fix/input-json-explicit-stdin

Conversation

@rafa-thayto

Copy link
Copy Markdown
Contributor

Summary

In agent mode the program-level --input-json expander consumed any non-TTY stdin and parsed it as the options payload, even when --input-json was never passed. That broke two common patterns:

# shell loops — the clerk process swallows the rest of the worklistwhileread -r app ins;do clerk config patch --app "$app" --instance "$ins" --json '' --yes;done< worklist.tsv
# commands that read their own stdin
cat payload.json | clerk api /users # body was pre-empted and parsed as --input-json

Non-JSON stdin then failed with invalid_json before the command ran. This makes stdin read only with an explicit --input-json -; piped stdin is otherwise left untouched.

Test plan

  • bun test src/lib/input-json.test.ts and src/test/integration/input-json.test.ts pass
  • Updated unit tests assert piped stdin is ignored without --input-json -

Fixes#333

@changeset-bot

changeset-botBot commented Jun 16, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 1d15c95

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
clerkPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitaiBot commented Jun 16, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 6a380fec-f78a-42e7-928b-bed85ea293f5

📥 Commits

Reviewing files that changed from the base of the PR and between 9662f59 and 1d15c95.

📒 Files selected for processing (4)
  • .changeset/input-json-explicit-stdin.md
  • packages/cli-core/src/commands/users/README.md
  • packages/cli-core/src/lib/input-json.test.ts
  • packages/cli-core/src/lib/input-json.ts
✅ Files skipped from review due to trivial changes (2)
  • .changeset/input-json-explicit-stdin.md
  • packages/cli-core/src/commands/users/README.md
🚧 Files skipped from review as they are similar to previous changes (2)
  • packages/cli-core/src/lib/input-json.ts
  • packages/cli-core/src/lib/input-json.test.ts

📝 Walkthrough

Walkthrough

expandInputJson now returns the original argv unchanged when --input-json is absent, and stdin is only read when --input-json - is explicitly provided. The helper that previously read optional piped stdin is removed. Tests now assert that piped JSON object, array, and non-JSON input are ignored without the flag, while the README and changeset document the updated behavior.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 66.67% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly and accurately summarizes the main change to stdin handling for --input-json.
Description check✅ PassedThe description is directly related to the stdin parsing fix and matches the documented behavior changes.
Linked Issues check✅ PassedThe PR satisfies #333 by only reading stdin with explicit --input-json - and updating tests accordingly.
Out of Scope Changes check✅ PassedThe code, tests, and docs changes all support the stdin-handling fix and do not appear unrelated.

Comment @coderabbitai help to get the list of available commands.

@wyattjohwyattjoh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One minor test-cleanup note inline. The fix itself is correct: stopping expandInputJson from implicitly draining stdin is the right call, since that stdin is shared with commands that read their own body (clerk api, clerk config push).

Comment threadpackages/cli-core/src/lib/input-json.test.ts
@rafa-thayto
rafa-thaytoforce-pushed the fix/input-json-explicit-stdin branch from 7d4ac9d to 9662f59CompareJune 26, 2026 19:59
Implicit stdin consumption (when stdin was not a TTY) parsed any piped data as
the --input-json options payload, breaking `while read` loops and commands
that read their own stdin (e.g. `cat body.json | clerk api`). Require the
explicit `--input-json -` marker instead.
Fixes#333
@rafa-thayto
rafa-thaytoforce-pushed the fix/input-json-explicit-stdin branch from 9662f59 to 1d15c95CompareJune 29, 2026 12:30
@rafa-thayto
rafa-thayto merged commit 393bf26 into mainJun 30, 2026
10 checks passed
@rafa-thayto
rafa-thayto deleted the fix/input-json-explicit-stdin branch June 30, 2026 14:48
@github-actionsgithub-actionsBot mentioned this pull request Jun 30, 2026
rafa-thayto added a commit to clerk/skills that referenced this pull request Jul 23, 2026
clerk/cli#341 removed implicit stdin auto-detection; --input-json now
reads stdin only with the explicit `-` marker. Update the skill so it
no longer teaches `echo '{...}' | clerk init` as a working pattern
(it now silently no-ops) and notes that bare piped stdin is left
untouched for shell loops and self-reading commands.
Claude-Session: https://claude.ai/code/session_01W6swrwZfwkAB5ye7EBy98z
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Agent mode parses any piped stdin as --input-json, breaking shell loops and preempting explicit flags

2 participants

@rafa-thayto@wyattjoh
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix(input-json): only read stdin with explicit `--input-json -` by rafa-thayto · Pull Request #341 · clerk/cli · GitHub
Skip to content

fix(input-json): only read stdin with explicit --input-json - - #341

Merged
rafa-thayto merged 2 commits into
mainfrom
fix/input-json-explicit-stdin
Jun 30, 2026
Merged

fix(input-json): only read stdin with explicit --input-json -#341
rafa-thayto merged 2 commits into
mainfrom
fix/input-json-explicit-stdin

Conversation

@rafa-thayto

Copy link
Copy Markdown
Contributor

Summary

In agent mode the program-level --input-json expander consumed any non-TTY stdin and parsed it as the options payload, even when --input-json was never passed. That broke two common patterns:

# shell loops — the clerk process swallows the rest of the worklistwhileread -r app ins;do clerk config patch --app "$app" --instance "$ins" --json '' --yes;done< worklist.tsv
# commands that read their own stdin
cat payload.json | clerk api /users # body was pre-empted and parsed as --input-json

Non-JSON stdin then failed with invalid_json before the command ran. This makes stdin read only with an explicit --input-json -; piped stdin is otherwise left untouched.

Test plan

  • bun test src/lib/input-json.test.ts and src/test/integration/input-json.test.ts pass
  • Updated unit tests assert piped stdin is ignored without --input-json -

Fixes#333

@changeset-bot

changeset-botBot commented Jun 16, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 1d15c95

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
clerkPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitaiBot commented Jun 16, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 6a380fec-f78a-42e7-928b-bed85ea293f5

📥 Commits

Reviewing files that changed from the base of the PR and between 9662f59 and 1d15c95.

📒 Files selected for processing (4)
  • .changeset/input-json-explicit-stdin.md
  • packages/cli-core/src/commands/users/README.md
  • packages/cli-core/src/lib/input-json.test.ts
  • packages/cli-core/src/lib/input-json.ts
✅ Files skipped from review due to trivial changes (2)
  • .changeset/input-json-explicit-stdin.md
  • packages/cli-core/src/commands/users/README.md
🚧 Files skipped from review as they are similar to previous changes (2)
  • packages/cli-core/src/lib/input-json.ts
  • packages/cli-core/src/lib/input-json.test.ts

📝 Walkthrough

Walkthrough

expandInputJson now returns the original argv unchanged when --input-json is absent, and stdin is only read when --input-json - is explicitly provided. The helper that previously read optional piped stdin is removed. Tests now assert that piped JSON object, array, and non-JSON input are ignored without the flag, while the README and changeset document the updated behavior.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 66.67% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly and accurately summarizes the main change to stdin handling for --input-json.
Description check✅ PassedThe description is directly related to the stdin parsing fix and matches the documented behavior changes.
Linked Issues check✅ PassedThe PR satisfies #333 by only reading stdin with explicit --input-json - and updating tests accordingly.
Out of Scope Changes check✅ PassedThe code, tests, and docs changes all support the stdin-handling fix and do not appear unrelated.

Comment @coderabbitai help to get the list of available commands.

@wyattjohwyattjoh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One minor test-cleanup note inline. The fix itself is correct: stopping expandInputJson from implicitly draining stdin is the right call, since that stdin is shared with commands that read their own body (clerk api, clerk config push).

Comment threadpackages/cli-core/src/lib/input-json.test.ts
@rafa-thayto
rafa-thaytoforce-pushed the fix/input-json-explicit-stdin branch from 7d4ac9d to 9662f59CompareJune 26, 2026 19:59
Implicit stdin consumption (when stdin was not a TTY) parsed any piped data as
the --input-json options payload, breaking `while read` loops and commands
that read their own stdin (e.g. `cat body.json | clerk api`). Require the
explicit `--input-json -` marker instead.
Fixes#333
@rafa-thayto
rafa-thaytoforce-pushed the fix/input-json-explicit-stdin branch from 9662f59 to 1d15c95CompareJune 29, 2026 12:30
@rafa-thayto
rafa-thayto merged commit 393bf26 into mainJun 30, 2026
10 checks passed
@rafa-thayto
rafa-thayto deleted the fix/input-json-explicit-stdin branch June 30, 2026 14:48
@github-actionsgithub-actionsBot mentioned this pull request Jun 30, 2026
rafa-thayto added a commit to clerk/skills that referenced this pull request Jul 23, 2026
clerk/cli#341 removed implicit stdin auto-detection; --input-json now
reads stdin only with the explicit `-` marker. Update the skill so it
no longer teaches `echo '{...}' | clerk init` as a working pattern
(it now silently no-ops) and notes that bare piped stdin is left
untouched for shell loops and self-reading commands.
Claude-Session: https://claude.ai/code/session_01W6swrwZfwkAB5ye7EBy98z
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Agent mode parses any piped stdin as --input-json, breaking shell loops and preempting explicit flags

2 participants

@rafa-thayto@wyattjoh
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(input-json): only read stdin with explicit `--input-json -` by rafa-thayto · Pull Request #341 · clerk/cli · GitHub
Skip to content

fix(input-json): only read stdin with explicit --input-json - - #341

Merged
rafa-thayto merged 2 commits into
mainfrom
fix/input-json-explicit-stdin
Jun 30, 2026
Merged

fix(input-json): only read stdin with explicit --input-json -#341
rafa-thayto merged 2 commits into
mainfrom
fix/input-json-explicit-stdin

Conversation

@rafa-thayto

Copy link
Copy Markdown
Contributor

Summary

In agent mode the program-level --input-json expander consumed any non-TTY stdin and parsed it as the options payload, even when --input-json was never passed. That broke two common patterns:

# shell loops — the clerk process swallows the rest of the worklistwhileread -r app ins;do clerk config patch --app "$app" --instance "$ins" --json '' --yes;done< worklist.tsv
# commands that read their own stdin
cat payload.json | clerk api /users # body was pre-empted and parsed as --input-json

Non-JSON stdin then failed with invalid_json before the command ran. This makes stdin read only with an explicit --input-json -; piped stdin is otherwise left untouched.

Test plan

  • bun test src/lib/input-json.test.ts and src/test/integration/input-json.test.ts pass
  • Updated unit tests assert piped stdin is ignored without --input-json -

Fixes#333

@changeset-bot

changeset-botBot commented Jun 16, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 1d15c95

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
clerkPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitaiBot commented Jun 16, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 6a380fec-f78a-42e7-928b-bed85ea293f5

📥 Commits

Reviewing files that changed from the base of the PR and between 9662f59 and 1d15c95.

📒 Files selected for processing (4)
  • .changeset/input-json-explicit-stdin.md
  • packages/cli-core/src/commands/users/README.md
  • packages/cli-core/src/lib/input-json.test.ts
  • packages/cli-core/src/lib/input-json.ts
✅ Files skipped from review due to trivial changes (2)
  • .changeset/input-json-explicit-stdin.md
  • packages/cli-core/src/commands/users/README.md
🚧 Files skipped from review as they are similar to previous changes (2)
  • packages/cli-core/src/lib/input-json.ts
  • packages/cli-core/src/lib/input-json.test.ts

📝 Walkthrough

Walkthrough

expandInputJson now returns the original argv unchanged when --input-json is absent, and stdin is only read when --input-json - is explicitly provided. The helper that previously read optional piped stdin is removed. Tests now assert that piped JSON object, array, and non-JSON input are ignored without the flag, while the README and changeset document the updated behavior.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 66.67% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly and accurately summarizes the main change to stdin handling for --input-json.
Description check✅ PassedThe description is directly related to the stdin parsing fix and matches the documented behavior changes.
Linked Issues check✅ PassedThe PR satisfies #333 by only reading stdin with explicit --input-json - and updating tests accordingly.
Out of Scope Changes check✅ PassedThe code, tests, and docs changes all support the stdin-handling fix and do not appear unrelated.

Comment @coderabbitai help to get the list of available commands.

@wyattjohwyattjoh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One minor test-cleanup note inline. The fix itself is correct: stopping expandInputJson from implicitly draining stdin is the right call, since that stdin is shared with commands that read their own body (clerk api, clerk config push).

Comment threadpackages/cli-core/src/lib/input-json.test.ts
@rafa-thayto
rafa-thaytoforce-pushed the fix/input-json-explicit-stdin branch from 7d4ac9d to 9662f59CompareJune 26, 2026 19:59
Implicit stdin consumption (when stdin was not a TTY) parsed any piped data as
the --input-json options payload, breaking `while read` loops and commands
that read their own stdin (e.g. `cat body.json | clerk api`). Require the
explicit `--input-json -` marker instead.
Fixes#333
@rafa-thayto
rafa-thaytoforce-pushed the fix/input-json-explicit-stdin branch from 9662f59 to 1d15c95CompareJune 29, 2026 12:30
@rafa-thayto
rafa-thayto merged commit 393bf26 into mainJun 30, 2026
10 checks passed
@rafa-thayto
rafa-thayto deleted the fix/input-json-explicit-stdin branch June 30, 2026 14:48
@github-actionsgithub-actionsBot mentioned this pull request Jun 30, 2026
rafa-thayto added a commit to clerk/skills that referenced this pull request Jul 23, 2026
clerk/cli#341 removed implicit stdin auto-detection; --input-json now
reads stdin only with the explicit `-` marker. Update the skill so it
no longer teaches `echo '{...}' | clerk init` as a working pattern
(it now silently no-ops) and notes that bare piped stdin is left
untouched for shell loops and self-reading commands.
Claude-Session: https://claude.ai/code/session_01W6swrwZfwkAB5ye7EBy98z
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Agent mode parses any piped stdin as --input-json, breaking shell loops and preempting explicit flags

2 participants

@rafa-thayto@wyattjoh
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(input-json): only read stdin with explicit `--input-json -` by rafa-thayto · Pull Request #341 · clerk/cli · GitHub
Skip to content

fix(input-json): only read stdin with explicit --input-json - - #341

Merged
rafa-thayto merged 2 commits into
mainfrom
fix/input-json-explicit-stdin
Jun 30, 2026
Merged

fix(input-json): only read stdin with explicit --input-json -#341
rafa-thayto merged 2 commits into
mainfrom
fix/input-json-explicit-stdin

Conversation

@rafa-thayto

Copy link
Copy Markdown
Contributor

Summary

In agent mode the program-level --input-json expander consumed any non-TTY stdin and parsed it as the options payload, even when --input-json was never passed. That broke two common patterns:

# shell loops — the clerk process swallows the rest of the worklistwhileread -r app ins;do clerk config patch --app "$app" --instance "$ins" --json '' --yes;done< worklist.tsv
# commands that read their own stdin
cat payload.json | clerk api /users # body was pre-empted and parsed as --input-json

Non-JSON stdin then failed with invalid_json before the command ran. This makes stdin read only with an explicit --input-json -; piped stdin is otherwise left untouched.

Test plan

  • bun test src/lib/input-json.test.ts and src/test/integration/input-json.test.ts pass
  • Updated unit tests assert piped stdin is ignored without --input-json -

Fixes#333

@changeset-bot

changeset-botBot commented Jun 16, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 1d15c95

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
clerkPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitaiBot commented Jun 16, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 6a380fec-f78a-42e7-928b-bed85ea293f5

📥 Commits

Reviewing files that changed from the base of the PR and between 9662f59 and 1d15c95.

📒 Files selected for processing (4)
  • .changeset/input-json-explicit-stdin.md
  • packages/cli-core/src/commands/users/README.md
  • packages/cli-core/src/lib/input-json.test.ts
  • packages/cli-core/src/lib/input-json.ts
✅ Files skipped from review due to trivial changes (2)
  • .changeset/input-json-explicit-stdin.md
  • packages/cli-core/src/commands/users/README.md
🚧 Files skipped from review as they are similar to previous changes (2)
  • packages/cli-core/src/lib/input-json.ts
  • packages/cli-core/src/lib/input-json.test.ts

📝 Walkthrough

Walkthrough

expandInputJson now returns the original argv unchanged when --input-json is absent, and stdin is only read when --input-json - is explicitly provided. The helper that previously read optional piped stdin is removed. Tests now assert that piped JSON object, array, and non-JSON input are ignored without the flag, while the README and changeset document the updated behavior.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 66.67% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly and accurately summarizes the main change to stdin handling for --input-json.
Description check✅ PassedThe description is directly related to the stdin parsing fix and matches the documented behavior changes.
Linked Issues check✅ PassedThe PR satisfies #333 by only reading stdin with explicit --input-json - and updating tests accordingly.
Out of Scope Changes check✅ PassedThe code, tests, and docs changes all support the stdin-handling fix and do not appear unrelated.

Comment @coderabbitai help to get the list of available commands.

@wyattjohwyattjoh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One minor test-cleanup note inline. The fix itself is correct: stopping expandInputJson from implicitly draining stdin is the right call, since that stdin is shared with commands that read their own body (clerk api, clerk config push).

Comment threadpackages/cli-core/src/lib/input-json.test.ts
@rafa-thayto
rafa-thaytoforce-pushed the fix/input-json-explicit-stdin branch from 7d4ac9d to 9662f59CompareJune 26, 2026 19:59
Implicit stdin consumption (when stdin was not a TTY) parsed any piped data as
the --input-json options payload, breaking `while read` loops and commands
that read their own stdin (e.g. `cat body.json | clerk api`). Require the
explicit `--input-json -` marker instead.
Fixes#333
@rafa-thayto
rafa-thaytoforce-pushed the fix/input-json-explicit-stdin branch from 9662f59 to 1d15c95CompareJune 29, 2026 12:30
@rafa-thayto
rafa-thayto merged commit 393bf26 into mainJun 30, 2026
10 checks passed
@rafa-thayto
rafa-thayto deleted the fix/input-json-explicit-stdin branch June 30, 2026 14:48
@github-actionsgithub-actionsBot mentioned this pull request Jun 30, 2026
rafa-thayto added a commit to clerk/skills that referenced this pull request Jul 23, 2026
clerk/cli#341 removed implicit stdin auto-detection; --input-json now
reads stdin only with the explicit `-` marker. Update the skill so it
no longer teaches `echo '{...}' | clerk init` as a working pattern
(it now silently no-ops) and notes that bare piped stdin is left
untouched for shell loops and self-reading commands.
Claude-Session: https://claude.ai/code/session_01W6swrwZfwkAB5ye7EBy98z
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Agent mode parses any piped stdin as --input-json, breaking shell loops and preempting explicit flags

2 participants

@rafa-thayto@wyattjoh
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix(input-json): only read stdin with explicit `--input-json -` by rafa-thayto · Pull Request #341 · clerk/cli · GitHub
Skip to content

fix(input-json): only read stdin with explicit --input-json - - #341

Merged
rafa-thayto merged 2 commits into
mainfrom
fix/input-json-explicit-stdin
Jun 30, 2026
Merged

fix(input-json): only read stdin with explicit --input-json -#341
rafa-thayto merged 2 commits into
mainfrom
fix/input-json-explicit-stdin

Conversation

@rafa-thayto

Copy link
Copy Markdown
Contributor

Summary

In agent mode the program-level --input-json expander consumed any non-TTY stdin and parsed it as the options payload, even when --input-json was never passed. That broke two common patterns:

# shell loops — the clerk process swallows the rest of the worklistwhileread -r app ins;do clerk config patch --app "$app" --instance "$ins" --json '' --yes;done< worklist.tsv
# commands that read their own stdin
cat payload.json | clerk api /users # body was pre-empted and parsed as --input-json

Non-JSON stdin then failed with invalid_json before the command ran. This makes stdin read only with an explicit --input-json -; piped stdin is otherwise left untouched.

Test plan

  • bun test src/lib/input-json.test.ts and src/test/integration/input-json.test.ts pass
  • Updated unit tests assert piped stdin is ignored without --input-json -

Fixes#333

@changeset-bot

changeset-botBot commented Jun 16, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 1d15c95

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
clerkPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitaiBot commented Jun 16, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 6a380fec-f78a-42e7-928b-bed85ea293f5

📥 Commits

Reviewing files that changed from the base of the PR and between 9662f59 and 1d15c95.

📒 Files selected for processing (4)
  • .changeset/input-json-explicit-stdin.md
  • packages/cli-core/src/commands/users/README.md
  • packages/cli-core/src/lib/input-json.test.ts
  • packages/cli-core/src/lib/input-json.ts
✅ Files skipped from review due to trivial changes (2)
  • .changeset/input-json-explicit-stdin.md
  • packages/cli-core/src/commands/users/README.md
🚧 Files skipped from review as they are similar to previous changes (2)
  • packages/cli-core/src/lib/input-json.ts
  • packages/cli-core/src/lib/input-json.test.ts

📝 Walkthrough

Walkthrough

expandInputJson now returns the original argv unchanged when --input-json is absent, and stdin is only read when --input-json - is explicitly provided. The helper that previously read optional piped stdin is removed. Tests now assert that piped JSON object, array, and non-JSON input are ignored without the flag, while the README and changeset document the updated behavior.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 66.67% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly and accurately summarizes the main change to stdin handling for --input-json.
Description check✅ PassedThe description is directly related to the stdin parsing fix and matches the documented behavior changes.
Linked Issues check✅ PassedThe PR satisfies #333 by only reading stdin with explicit --input-json - and updating tests accordingly.
Out of Scope Changes check✅ PassedThe code, tests, and docs changes all support the stdin-handling fix and do not appear unrelated.

Comment @coderabbitai help to get the list of available commands.

@wyattjohwyattjoh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One minor test-cleanup note inline. The fix itself is correct: stopping expandInputJson from implicitly draining stdin is the right call, since that stdin is shared with commands that read their own body (clerk api, clerk config push).

Comment threadpackages/cli-core/src/lib/input-json.test.ts
@rafa-thayto
rafa-thaytoforce-pushed the fix/input-json-explicit-stdin branch from 7d4ac9d to 9662f59CompareJune 26, 2026 19:59
Implicit stdin consumption (when stdin was not a TTY) parsed any piped data as
the --input-json options payload, breaking `while read` loops and commands
that read their own stdin (e.g. `cat body.json | clerk api`). Require the
explicit `--input-json -` marker instead.
Fixes#333
@rafa-thayto
rafa-thaytoforce-pushed the fix/input-json-explicit-stdin branch from 9662f59 to 1d15c95CompareJune 29, 2026 12:30
@rafa-thayto
rafa-thayto merged commit 393bf26 into mainJun 30, 2026
10 checks passed
@rafa-thayto
rafa-thayto deleted the fix/input-json-explicit-stdin branch June 30, 2026 14:48
@github-actionsgithub-actionsBot mentioned this pull request Jun 30, 2026
rafa-thayto added a commit to clerk/skills that referenced this pull request Jul 23, 2026
clerk/cli#341 removed implicit stdin auto-detection; --input-json now
reads stdin only with the explicit `-` marker. Update the skill so it
no longer teaches `echo '{...}' | clerk init` as a working pattern
(it now silently no-ops) and notes that bare piped stdin is left
untouched for shell loops and self-reading commands.
Claude-Session: https://claude.ai/code/session_01W6swrwZfwkAB5ye7EBy98z
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Agent mode parses any piped stdin as --input-json, breaking shell loops and preempting explicit flags

2 participants

@rafa-thayto@wyattjoh
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(input-json): only read stdin with explicit `--input-json -` by rafa-thayto · Pull Request #341 · clerk/cli · GitHub
Skip to content

fix(input-json): only read stdin with explicit --input-json - - #341

Merged
rafa-thayto merged 2 commits into
mainfrom
fix/input-json-explicit-stdin
Jun 30, 2026
Merged

fix(input-json): only read stdin with explicit --input-json -#341
rafa-thayto merged 2 commits into
mainfrom
fix/input-json-explicit-stdin

Conversation

@rafa-thayto

Copy link
Copy Markdown
Contributor

Summary

In agent mode the program-level --input-json expander consumed any non-TTY stdin and parsed it as the options payload, even when --input-json was never passed. That broke two common patterns:

# shell loops — the clerk process swallows the rest of the worklistwhileread -r app ins;do clerk config patch --app "$app" --instance "$ins" --json '' --yes;done< worklist.tsv
# commands that read their own stdin
cat payload.json | clerk api /users # body was pre-empted and parsed as --input-json

Non-JSON stdin then failed with invalid_json before the command ran. This makes stdin read only with an explicit --input-json -; piped stdin is otherwise left untouched.

Test plan

  • bun test src/lib/input-json.test.ts and src/test/integration/input-json.test.ts pass
  • Updated unit tests assert piped stdin is ignored without --input-json -

Fixes#333

@changeset-bot

changeset-botBot commented Jun 16, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 1d15c95

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
clerkPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitaiBot commented Jun 16, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 6a380fec-f78a-42e7-928b-bed85ea293f5

📥 Commits

Reviewing files that changed from the base of the PR and between 9662f59 and 1d15c95.

📒 Files selected for processing (4)
  • .changeset/input-json-explicit-stdin.md
  • packages/cli-core/src/commands/users/README.md
  • packages/cli-core/src/lib/input-json.test.ts
  • packages/cli-core/src/lib/input-json.ts
✅ Files skipped from review due to trivial changes (2)
  • .changeset/input-json-explicit-stdin.md
  • packages/cli-core/src/commands/users/README.md
🚧 Files skipped from review as they are similar to previous changes (2)
  • packages/cli-core/src/lib/input-json.ts
  • packages/cli-core/src/lib/input-json.test.ts

📝 Walkthrough

Walkthrough

expandInputJson now returns the original argv unchanged when --input-json is absent, and stdin is only read when --input-json - is explicitly provided. The helper that previously read optional piped stdin is removed. Tests now assert that piped JSON object, array, and non-JSON input are ignored without the flag, while the README and changeset document the updated behavior.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 66.67% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly and accurately summarizes the main change to stdin handling for --input-json.
Description check✅ PassedThe description is directly related to the stdin parsing fix and matches the documented behavior changes.
Linked Issues check✅ PassedThe PR satisfies #333 by only reading stdin with explicit --input-json - and updating tests accordingly.
Out of Scope Changes check✅ PassedThe code, tests, and docs changes all support the stdin-handling fix and do not appear unrelated.

Comment @coderabbitai help to get the list of available commands.

@wyattjohwyattjoh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One minor test-cleanup note inline. The fix itself is correct: stopping expandInputJson from implicitly draining stdin is the right call, since that stdin is shared with commands that read their own body (clerk api, clerk config push).

Comment threadpackages/cli-core/src/lib/input-json.test.ts
@rafa-thayto
rafa-thaytoforce-pushed the fix/input-json-explicit-stdin branch from 7d4ac9d to 9662f59CompareJune 26, 2026 19:59
Implicit stdin consumption (when stdin was not a TTY) parsed any piped data as
the --input-json options payload, breaking `while read` loops and commands
that read their own stdin (e.g. `cat body.json | clerk api`). Require the
explicit `--input-json -` marker instead.
Fixes#333
@rafa-thayto
rafa-thaytoforce-pushed the fix/input-json-explicit-stdin branch from 9662f59 to 1d15c95CompareJune 29, 2026 12:30
@rafa-thayto
rafa-thayto merged commit 393bf26 into mainJun 30, 2026
10 checks passed
@rafa-thayto
rafa-thayto deleted the fix/input-json-explicit-stdin branch June 30, 2026 14:48
@github-actionsgithub-actionsBot mentioned this pull request Jun 30, 2026
rafa-thayto added a commit to clerk/skills that referenced this pull request Jul 23, 2026
clerk/cli#341 removed implicit stdin auto-detection; --input-json now
reads stdin only with the explicit `-` marker. Update the skill so it
no longer teaches `echo '{...}' | clerk init` as a working pattern
(it now silently no-ops) and notes that bare piped stdin is left
untouched for shell loops and self-reading commands.
Claude-Session: https://claude.ai/code/session_01W6swrwZfwkAB5ye7EBy98z
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Agent mode parses any piped stdin as --input-json, breaking shell loops and preempting explicit flags

2 participants

@rafa-thayto@wyattjoh
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(input-json): only read stdin with explicit `--input-json -` by rafa-thayto · Pull Request #341 · clerk/cli · GitHub
Skip to content

fix(input-json): only read stdin with explicit --input-json - - #341

Merged
rafa-thayto merged 2 commits into
mainfrom
fix/input-json-explicit-stdin
Jun 30, 2026
Merged

fix(input-json): only read stdin with explicit --input-json -#341
rafa-thayto merged 2 commits into
mainfrom
fix/input-json-explicit-stdin

Conversation

@rafa-thayto

Copy link
Copy Markdown
Contributor

Summary

In agent mode the program-level --input-json expander consumed any non-TTY stdin and parsed it as the options payload, even when --input-json was never passed. That broke two common patterns:

# shell loops — the clerk process swallows the rest of the worklistwhileread -r app ins;do clerk config patch --app "$app" --instance "$ins" --json '' --yes;done< worklist.tsv
# commands that read their own stdin
cat payload.json | clerk api /users # body was pre-empted and parsed as --input-json

Non-JSON stdin then failed with invalid_json before the command ran. This makes stdin read only with an explicit --input-json -; piped stdin is otherwise left untouched.

Test plan

  • bun test src/lib/input-json.test.ts and src/test/integration/input-json.test.ts pass
  • Updated unit tests assert piped stdin is ignored without --input-json -

Fixes#333

@changeset-bot

changeset-botBot commented Jun 16, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 1d15c95

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
clerkPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitaiBot commented Jun 16, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 6a380fec-f78a-42e7-928b-bed85ea293f5

📥 Commits

Reviewing files that changed from the base of the PR and between 9662f59 and 1d15c95.

📒 Files selected for processing (4)
  • .changeset/input-json-explicit-stdin.md
  • packages/cli-core/src/commands/users/README.md
  • packages/cli-core/src/lib/input-json.test.ts
  • packages/cli-core/src/lib/input-json.ts
✅ Files skipped from review due to trivial changes (2)
  • .changeset/input-json-explicit-stdin.md
  • packages/cli-core/src/commands/users/README.md
🚧 Files skipped from review as they are similar to previous changes (2)
  • packages/cli-core/src/lib/input-json.ts
  • packages/cli-core/src/lib/input-json.test.ts

📝 Walkthrough

Walkthrough

expandInputJson now returns the original argv unchanged when --input-json is absent, and stdin is only read when --input-json - is explicitly provided. The helper that previously read optional piped stdin is removed. Tests now assert that piped JSON object, array, and non-JSON input are ignored without the flag, while the README and changeset document the updated behavior.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 66.67% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly and accurately summarizes the main change to stdin handling for --input-json.
Description check✅ PassedThe description is directly related to the stdin parsing fix and matches the documented behavior changes.
Linked Issues check✅ PassedThe PR satisfies #333 by only reading stdin with explicit --input-json - and updating tests accordingly.
Out of Scope Changes check✅ PassedThe code, tests, and docs changes all support the stdin-handling fix and do not appear unrelated.

Comment @coderabbitai help to get the list of available commands.

@wyattjohwyattjoh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One minor test-cleanup note inline. The fix itself is correct: stopping expandInputJson from implicitly draining stdin is the right call, since that stdin is shared with commands that read their own body (clerk api, clerk config push).

Comment threadpackages/cli-core/src/lib/input-json.test.ts
@rafa-thayto
rafa-thaytoforce-pushed the fix/input-json-explicit-stdin branch from 7d4ac9d to 9662f59CompareJune 26, 2026 19:59
Implicit stdin consumption (when stdin was not a TTY) parsed any piped data as
the --input-json options payload, breaking `while read` loops and commands
that read their own stdin (e.g. `cat body.json | clerk api`). Require the
explicit `--input-json -` marker instead.
Fixes#333
@rafa-thayto
rafa-thaytoforce-pushed the fix/input-json-explicit-stdin branch from 9662f59 to 1d15c95CompareJune 29, 2026 12:30
@rafa-thayto
rafa-thayto merged commit 393bf26 into mainJun 30, 2026
10 checks passed
@rafa-thayto
rafa-thayto deleted the fix/input-json-explicit-stdin branch June 30, 2026 14:48
@github-actionsgithub-actionsBot mentioned this pull request Jun 30, 2026
rafa-thayto added a commit to clerk/skills that referenced this pull request Jul 23, 2026
clerk/cli#341 removed implicit stdin auto-detection; --input-json now
reads stdin only with the explicit `-` marker. Update the skill so it
no longer teaches `echo '{...}' | clerk init` as a working pattern
(it now silently no-ops) and notes that bare piped stdin is left
untouched for shell loops and self-reading commands.
Claude-Session: https://claude.ai/code/session_01W6swrwZfwkAB5ye7EBy98z
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Agent mode parses any piped stdin as --input-json, breaking shell loops and preempting explicit flags

2 participants

@rafa-thayto@wyattjoh
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); fix(input-json): only read stdin with explicit `--input-json -` by rafa-thayto · Pull Request #341 · clerk/cli · GitHub
Skip to content

fix(input-json): only read stdin with explicit --input-json - - #341

Merged
rafa-thayto merged 2 commits into
mainfrom
fix/input-json-explicit-stdin
Jun 30, 2026
Merged

fix(input-json): only read stdin with explicit --input-json -#341
rafa-thayto merged 2 commits into
mainfrom
fix/input-json-explicit-stdin

Conversation

@rafa-thayto

Copy link
Copy Markdown
Contributor

Summary

In agent mode the program-level --input-json expander consumed any non-TTY stdin and parsed it as the options payload, even when --input-json was never passed. That broke two common patterns:

# shell loops — the clerk process swallows the rest of the worklistwhileread -r app ins;do clerk config patch --app "$app" --instance "$ins" --json '' --yes;done< worklist.tsv
# commands that read their own stdin
cat payload.json | clerk api /users # body was pre-empted and parsed as --input-json

Non-JSON stdin then failed with invalid_json before the command ran. This makes stdin read only with an explicit --input-json -; piped stdin is otherwise left untouched.

Test plan

  • bun test src/lib/input-json.test.ts and src/test/integration/input-json.test.ts pass
  • Updated unit tests assert piped stdin is ignored without --input-json -

Fixes#333

@changeset-bot

changeset-botBot commented Jun 16, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 1d15c95

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
clerkPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitaiBot commented Jun 16, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 6a380fec-f78a-42e7-928b-bed85ea293f5

📥 Commits

Reviewing files that changed from the base of the PR and between 9662f59 and 1d15c95.

📒 Files selected for processing (4)
  • .changeset/input-json-explicit-stdin.md
  • packages/cli-core/src/commands/users/README.md
  • packages/cli-core/src/lib/input-json.test.ts
  • packages/cli-core/src/lib/input-json.ts
✅ Files skipped from review due to trivial changes (2)
  • .changeset/input-json-explicit-stdin.md
  • packages/cli-core/src/commands/users/README.md
🚧 Files skipped from review as they are similar to previous changes (2)
  • packages/cli-core/src/lib/input-json.ts
  • packages/cli-core/src/lib/input-json.test.ts

📝 Walkthrough

Walkthrough

expandInputJson now returns the original argv unchanged when --input-json is absent, and stdin is only read when --input-json - is explicitly provided. The helper that previously read optional piped stdin is removed. Tests now assert that piped JSON object, array, and non-JSON input are ignored without the flag, while the README and changeset document the updated behavior.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 66.67% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly and accurately summarizes the main change to stdin handling for --input-json.
Description check✅ PassedThe description is directly related to the stdin parsing fix and matches the documented behavior changes.
Linked Issues check✅ PassedThe PR satisfies #333 by only reading stdin with explicit --input-json - and updating tests accordingly.
Out of Scope Changes check✅ PassedThe code, tests, and docs changes all support the stdin-handling fix and do not appear unrelated.

Comment @coderabbitai help to get the list of available commands.

@wyattjohwyattjoh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One minor test-cleanup note inline. The fix itself is correct: stopping expandInputJson from implicitly draining stdin is the right call, since that stdin is shared with commands that read their own body (clerk api, clerk config push).

Comment threadpackages/cli-core/src/lib/input-json.test.ts
@rafa-thayto
rafa-thaytoforce-pushed the fix/input-json-explicit-stdin branch from 7d4ac9d to 9662f59CompareJune 26, 2026 19:59
Implicit stdin consumption (when stdin was not a TTY) parsed any piped data as
the --input-json options payload, breaking `while read` loops and commands
that read their own stdin (e.g. `cat body.json | clerk api`). Require the
explicit `--input-json -` marker instead.
Fixes#333
@rafa-thayto
rafa-thaytoforce-pushed the fix/input-json-explicit-stdin branch from 9662f59 to 1d15c95CompareJune 29, 2026 12:30
@rafa-thayto
rafa-thayto merged commit 393bf26 into mainJun 30, 2026
10 checks passed
@rafa-thayto
rafa-thayto deleted the fix/input-json-explicit-stdin branch June 30, 2026 14:48
@github-actionsgithub-actionsBot mentioned this pull request Jun 30, 2026
rafa-thayto added a commit to clerk/skills that referenced this pull request Jul 23, 2026
clerk/cli#341 removed implicit stdin auto-detection; --input-json now
reads stdin only with the explicit `-` marker. Update the skill so it
no longer teaches `echo '{...}' | clerk init` as a working pattern
(it now silently no-ops) and notes that bare piped stdin is left
untouched for shell loops and self-reading commands.
Claude-Session: https://claude.ai/code/session_01W6swrwZfwkAB5ye7EBy98z
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Agent mode parses any piped stdin as --input-json, breaking shell loops and preempting explicit flags

2 participants

@rafa-thayto@wyattjoh