feat: 實作 bear CLI 骨架與 PAT 模式共用基礎(issue #6)
- 專案骨架:Elixir + Mix escript(單檔可執行 bear),HTTP 一律 Req - 設定/憑證檔讀寫:0600、原子寫入(rename)、O_CREAT|O_EXCL 防 symlink - PAT Bearer 呼叫 /userinfo;--json 輸出;規格化退出碼 - 補齊 main 規格承諾的 BEAR_TOKEN 環境變數(優先於憑證檔、不寫入) - login 無效 PAT 退出碼 3(依 docs/commands.md §3.1);token --refresh 用法錯誤 2(§3.3) - 35 個單元測試;mix precommit(compile --warnings-as-errors + format + test)全綠 - 沿用已關閉 PR #3 的實作(feat/pat-mode-mvp 分支),文件改依 main 現行版本更新 apps 管理指令待 #5 規格與 alterminal/bear#28 API 就緒後實作。
This commit is contained in:
+31
-2
@@ -1,7 +1,7 @@
|
||||
# Bear CLI 指令規劃(Command Spec)
|
||||
|
||||
> 狀態:規劃草案(對應 issue #19「創建 bear cli 倉庫」)
|
||||
> 範圍:**本文件只規劃指令介面,不實作程式碼**。
|
||||
> 狀態:P2 PAT 模式 MVP 已實作(見第 9 節);Device Flow 待伺服器端 P1。
|
||||
> 範圍:本文件為指令介面規格;App 管理指令(`bear apps` CRUD)另見 #5 規劃。
|
||||
> 登入採用的 OIDC Device Authorization Grant(RFC 8628)細節,見 bear 倉庫 `docs/cli-feature-plan.md`(issue #17)。
|
||||
> 另支援以**個人存取權杖(PAT)**登入(bear 已於 profile 頁提供 PAT 建立/列表/撤銷,`/userinfo` 接受 PAT 作為 Bearer)。
|
||||
|
||||
@@ -255,3 +255,32 @@ bear apps
|
||||
| `token --refresh` | `POST /token`(refresh_token,僅 Device Flow) |
|
||||
| `logout` | `POST /revoke`(僅 Device Flow;PAT 僅本機刪除,撤銷走網頁 `/profile/tokens`) |
|
||||
| `apps`(P3) | 待新增「公開應用清單」API |
|
||||
|
||||
---
|
||||
|
||||
## 9. 現行實作狀態(PAT 模式 MVP,issue #6)
|
||||
|
||||
目前實作為 **PAT 模式 MVP**(Elixir + Req、mix escript),與上方 Device Flow 規格的差異:
|
||||
|
||||
| 指令 | 原規格(Device Flow) | 現行實作(PAT 模式) |
|
||||
|------|----------------------|----------------------|
|
||||
| `login` | 裝置碼流程 | `--token <PAT>` 驗證 `GET /userinfo` 後保存(`-` 可從 stdin 讀);未給 `--token` 時提示 Device Flow 尚未開放(退出碼 2) |
|
||||
| `whoami` | `GET /userinfo`(refresh 輪轉) | `GET /userinfo`(Bearer PAT,無輪轉);`BEAR_TOKEN` 提供時優先使用 |
|
||||
| `token` | refresh token 輪轉換新 | 直接印出 PAT;`--refresh` 為用法錯誤(退出碼 2);`BEAR_TOKEN` 提供時優先印出 |
|
||||
| `logout` | `POST /revoke`(撤銷 refresh token) | 僅清除本機憑證;PAT 需至網頁 `/profile/tokens` 撤銷 |
|
||||
| `status` | 顯示 access token 剩餘秒數 | 純本機判定:顯示模式(PAT/BEAR_TOKEN 環境變數)與 issuer |
|
||||
| `apps` | P3 暫緩 | 未實作;App 管理指令規格見 #5,伺服器端 API 見 alterminal/bear#28 |
|
||||
|
||||
退出碼差異:`login`/`whoami` 的 token 無效(401)依 §3.1 為 `3`(本節實作一致)。
|
||||
|
||||
憑證檔結構(PAT 模式,0600、原子寫入、O_EXCL):
|
||||
|
||||
```json
|
||||
{"issuer": "https://alterminal.com", "access_token": "<PAT>", "email": "..."}
|
||||
```
|
||||
|
||||
建置:
|
||||
|
||||
```bash
|
||||
mix deps.get && mix test && mix escript.build # 產生單檔可執行 bear
|
||||
```
|
||||
|
||||
Reference in New Issue
Block a user