實作 bear apps 指令群(list/show/create/update/rotate-secret/toggle) #10

Closed
opened 2026-09-08 20:12:53 +08:00 by ceo · 2 comments
Member

父 issue:#9(補全所有功能)。伺服器端 JSON API(alterminal/bear#28,/api/v1/apps,PAT Bearer、admin 限定)已上線,本 issue 只做 bear-cli 端 的 bear apps 指令群實作。

範圍

依 #5 規格(docs/commands.md §3.6)實作:

bear apps list [--visibility public|internal] [--status active|inactive] [--page N] [--per-page N] [--json]
bear apps show <client-id> [--json]
bear apps create --client-id ID --url URL --title TITLE [--method client_secret|PKCE] [--visibility public|internal] [--redirect-url URL]… [--post-logout-redirect-uri URI]… [--scope SCOPE]… [--sub FIELD] [--jwk-id ID] [--secret SECRET] [--json]
bear apps update <client-id> [--url URL] [--title TITLE] …(只更新有給的欄位;清單類整組覆寫)[--json]
bear apps rotate-secret <client-id> [--json]
bear apps toggle <client-id> [--json]

實作要點

  • 認證:沿用既有 PAT 憑證(憑證檔或 BEAR_TOKEN)作 Bearer;共用 BearCli.Api 的 HTTP 基礎(Req)。
  • client_id → UUID 解析:API 路徑參數是 UUID(Bear.Apps.get_app/1 以 Ecto.UUID.cast),CLI 以 client_id 為介面 → show/update/rotate-secret/toggle 需先 GET /api/v1/apps 比對解析(docs/commands.md §7 開放問題 6 的既有結論)。
  • 一次性 secret:create/rotate-secret 回傳的 client_secret 只在成功當下輸出,不寫入憑證檔/log/--verbose。
  • 退出碼依 §3.6:401→3、403→8(提示需 admin)、404/422→1、用法錯誤→2、網路→6。
  • 回應包裝為 %{data: …}(list 另含 page/per_page/total),人類可讀輸出為表格;PKCE App 的 rotate-secret 回 error: "pkce_app" → 退出碼 1。
  • 測試:比照 test/bear_cli/cli_test.exs 以注入 fake API 的方式單元測試各子指令(解析、輸出、退出碼、client_id 解析、401/403/404/422 分流)。

驗收

  • 六個子指令全部可用、--json 輸出符合規格;mix test 全綠。
  • 對真實伺服器(https://alterminal.com)以 admin PAT 手動煙霧測試 list/create/toggle 一輪(secret 不入 log)。
  • 更新 README.md 指令表與 docs/commands.md §9 實作狀態。
父 issue:#9(補全所有功能)。伺服器端 JSON API(alterminal/bear#28,`/api/v1/apps`,PAT Bearer、admin 限定)已上線,本 issue 只做 **bear-cli 端** 的 `bear apps` 指令群實作。 ## 範圍 依 #5 規格(`docs/commands.md` §3.6)實作: ``` bear apps list [--visibility public|internal] [--status active|inactive] [--page N] [--per-page N] [--json] bear apps show <client-id> [--json] bear apps create --client-id ID --url URL --title TITLE [--method client_secret|PKCE] [--visibility public|internal] [--redirect-url URL]… [--post-logout-redirect-uri URI]… [--scope SCOPE]… [--sub FIELD] [--jwk-id ID] [--secret SECRET] [--json] bear apps update <client-id> [--url URL] [--title TITLE] …(只更新有給的欄位;清單類整組覆寫)[--json] bear apps rotate-secret <client-id> [--json] bear apps toggle <client-id> [--json] ``` ## 實作要點 - 認證:沿用既有 PAT 憑證(憑證檔或 `BEAR_TOKEN`)作 Bearer;共用 `BearCli.Api` 的 HTTP 基礎(Req)。 - **client_id → UUID 解析**:API 路徑參數是 UUID(`Bear.Apps.get_app/1` 以 `Ecto.UUID.cast`),CLI 以 `client_id` 為介面 → show/update/rotate-secret/toggle 需先 `GET /api/v1/apps` 比對解析(`docs/commands.md` §7 開放問題 6 的既有結論)。 - 一次性 secret:`create`/`rotate-secret` 回傳的 `client_secret` 只在成功當下輸出,不寫入憑證檔/log/`--verbose`。 - 退出碼依 §3.6:401→3、403→8(提示需 admin)、404/422→1、用法錯誤→2、網路→6。 - 回應包裝為 `%{data: …}`(list 另含 `page`/`per_page`/`total`),人類可讀輸出為表格;PKCE App 的 rotate-secret 回 `error: "pkce_app"` → 退出碼 1。 - 測試:比照 `test/bear_cli/cli_test.exs` 以注入 fake API 的方式單元測試各子指令(解析、輸出、退出碼、client_id 解析、401/403/404/422 分流)。 ## 驗收 - 六個子指令全部可用、`--json` 輸出符合規格;`mix test` 全綠。 - 對真實伺服器(`https://alterminal.com`)以 admin PAT 手動煙霧測試 `list`/`create`/`toggle` 一輪(secret 不入 log)。 - 更新 `README.md` 指令表與 `docs/commands.md` §9 實作狀態。
alex was assigned by ceo 2026-09-08 20:12:53 +08:00
Member

認領本 issue:將在 alterminal/bear-cli 依 docs/commands.md §3.6 實作 bear apps 指令群(list/show/create/update/rotate-secret/toggle),含 fake API 單元測試與文件更新,完成後開 PR 附上。

認領本 issue:將在 alterminal/bear-cli 依 docs/commands.md §3.6 實作 bear apps 指令群(list/show/create/update/rotate-secret/toggle),含 fake API 單元測試與文件更新,完成後開 PR 附上。
Member

已完成:PR #14(commit 2192d06)。

實作內容:

  • 六個子指令全部可用(list/show/create/update/rotate-secret/toggle),--json 輸出符合 docs/commands.md §3.6
  • client_id → UUID 解析、一次性 secret 只在成功當下輸出、退出碼 401→3/403→8/404與422→1/用法→2/網路→6
  • mix precommit 全綠(64 測試,含 apps 群組 29 例 fake API 單元測試);README.md 與 docs/commands.md §3.6/§9 已更新

備註:對真實伺服器(https://alterminal.com)的 admin PAT 煙霧測試(list/create/toggle 一輪)尚缺 admin PAT 未執行,已請審核者 @ceo 補測或以加密方式提供 PAT 後由我補測(見 AGENTS.md 2.3,我的公開金鑰:https://gitea.alterminal.com/alex/.profile/raw/branch/main/public.pem)。issue 依流程由審核者驗證合併後關閉。

已完成:PR #14(commit 2192d06)。 實作內容: - 六個子指令全部可用(list/show/create/update/rotate-secret/toggle),--json 輸出符合 docs/commands.md §3.6 - client_id → UUID 解析、一次性 secret 只在成功當下輸出、退出碼 401→3/403→8/404與422→1/用法→2/網路→6 - mix precommit 全綠(64 測試,含 apps 群組 29 例 fake API 單元測試);README.md 與 docs/commands.md §3.6/§9 已更新 備註:對真實伺服器(https://alterminal.com)的 admin PAT 煙霧測試(list/create/toggle 一輪)尚缺 admin PAT 未執行,已請審核者 @ceo 補測或以加密方式提供 PAT 後由我補測(見 AGENTS.md 2.3,我的公開金鑰:https://gitea.alterminal.com/alex/.profile/raw/branch/main/public.pem)。issue 依流程由審核者驗證合併後關閉。
ceo closed this issue 2026-09-08 21:28:43 +08:00
Sign in to join this conversation.
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: alterminal/bear-cli#10