feat: 實作個人自助指令群(issue #11) #15

Merged
queena merged 1 commits from feat/self-service-commands into main 2026-09-10 01:08:17 +08:00
Member

依 docs/commands.md §3.7 規格(PR #13)實作個人自助指令群,對接 alterminal/bear#38 已上線的 /api/v1/profile* JSON API(PAT Bearer、任何有效帳號)。關聯 issue #11(父 issue #9)。

內容

  • lib/bear_cli/self_service.ex(新):六個子群組——
    • profile show/profile set(20 個欄位選項、部分更新;--gender 列舉與 URL 類欄位本地驗證 → 用法錯誤 2)
    • password change(互動輸入舊/新/確認,不接受命令列明文;兩次不一致本地退出 2)
    • email change --new EMAIL(雙向驗證碼流程;429 限流 → 退出 1)
    • sessions list/revoke <id>/revoke-others(表格輸出;user_agent 截斷、--json 完整)
    • tokens list/create --name [--expires-in DAYS|never]/revoke <id>(明文只在 create 成功當下輸出一次)
    • mfa status/setup/disable/recovery-codes(setup 兩步:取 secret → 本地 ASCII QR(eqrcode)→ /mfa/setup/confirm 帶碼確認 → 一次性 recovery codes)
  • lib/bear_cli/api.ex:新增 profile 系列端點(profile/password/email/sessions/tokens/mfa)與 429 分流;共用請求輔助改名 api_request/5。
  • lib/bear_cli/cli.ex:六個指令群的解析、本地用法驗證與分派;--help 補個人自助指令群說明。
  • mix.exs:新增 eqrcode ~ 0.2(QR 本地生成,不經伺服器)。
  • 文件:docs/commands.md §3.7 對齊 #38 實際 API(mfa 確認端點為 /mfa/setup/confirm;sessions 回應無 expires_at;tokens create 不接受 --scope;email 確認需重帶 new_email;password body 含 password_confirmation),§7 開放問題 7/8 記錄 #38 結論,§8/§9 與 README 同步。
  • 測試:test/bear_cli/self_service_test.exs 50 例(fake API+互動輸入注入):解析、輸出、退出碼、一次性明文、401/403/404/422/429/網路錯誤分流、非 TTY。

驗證

  • mix precommit(compile --warnings-as-errors + format + test)全綠:114 passed(原 64 + 新 50)。
  • mix escript.build 後手動煙霧測試:--help、用法錯誤(退出 2)、無憑證(退出 3)、BEAR_TOKEN 下 401(退出 3)、非 TTY 互動指令(退出 2)皆符合規格。

注意

  • 敏感輸入一律互動提示;escript 環境暫以 IO.gets 讀取(不回顯需終端機 raw mode,未來可再強化,已在 §7 開放問題脈絡下處理規格面)。
  • 不自行合併;請審核後決定。

closes #11 - 本 PR 合併時自動關閉子 issue #11, 對應下方巡查留言的收尾提醒; 父 issue #9 續由其追蹤清單管理.

依 docs/commands.md §3.7 規格(PR #13)實作個人自助指令群,對接 alterminal/bear#38 已上線的 `/api/v1/profile*` JSON API(PAT Bearer、任何有效帳號)。關聯 issue #11(父 issue #9)。 ## 內容 - **`lib/bear_cli/self_service.ex`(新)**:六個子群組—— - `profile show`/`profile set`(20 個欄位選項、部分更新;`--gender` 列舉與 URL 類欄位本地驗證 → 用法錯誤 2) - `password change`(互動輸入舊/新/確認,不接受命令列明文;兩次不一致本地退出 2) - `email change --new EMAIL`(雙向驗證碼流程;429 限流 → 退出 1) - `sessions list`/`revoke <id>`/`revoke-others`(表格輸出;user_agent 截斷、--json 完整) - `tokens list`/`create --name [--expires-in DAYS|never]`/`revoke <id>`(明文只在 create 成功當下輸出一次) - `mfa status`/`setup`/`disable`/`recovery-codes`(setup 兩步:取 secret → 本地 ASCII QR(eqrcode)→ `/mfa/setup/confirm` 帶碼確認 → 一次性 recovery codes) - **`lib/bear_cli/api.ex`**:新增 profile 系列端點(profile/password/email/sessions/tokens/mfa)與 429 分流;共用請求輔助改名 `api_request/5`。 - **`lib/bear_cli/cli.ex`**:六個指令群的解析、本地用法驗證與分派;`--help` 補個人自助指令群說明。 - **`mix.exs`**:新增 `eqrcode ~ 0.2`(QR 本地生成,不經伺服器)。 - **文件**:`docs/commands.md` §3.7 對齊 #38 實際 API(mfa 確認端點為 `/mfa/setup/confirm`;sessions 回應無 `expires_at`;tokens create 不接受 `--scope`;email 確認需重帶 `new_email`;password body 含 `password_confirmation`),§7 開放問題 7/8 記錄 #38 結論,§8/§9 與 README 同步。 - **測試**:`test/bear_cli/self_service_test.exs` 50 例(fake API+互動輸入注入):解析、輸出、退出碼、一次性明文、401/403/404/422/429/網路錯誤分流、非 TTY。 ## 驗證 - `mix precommit`(compile --warnings-as-errors + format + test)全綠:**114 passed**(原 64 + 新 50)。 - `mix escript.build` 後手動煙霧測試:`--help`、用法錯誤(退出 2)、無憑證(退出 3)、`BEAR_TOKEN` 下 401(退出 3)、非 TTY 互動指令(退出 2)皆符合規格。 ## 注意 - 敏感輸入一律互動提示;escript 環境暫以 `IO.gets` 讀取(不回顯需終端機 raw mode,未來可再強化,已在 §7 開放問題脈絡下處理規格面)。 - 不自行合併;請審核後決定。 --- closes #11 - 本 PR 合併時自動關閉子 issue #11, 對應下方巡查留言的收尾提醒; 父 issue #9 續由其追蹤清單管理.
iris added 1 commit 2026-09-09 22:51:14 +08:00
- lib/bear_cli/self_service.ex:六個子群組(profile show/set、password change、
  email change、sessions list/revoke/revoke-others、tokens list/create/revoke、
  mfa status/setup/disable/recovery-codes),對接 alterminal/bear#38 的
  /api/v1/profile* JSON API(PAT Bearer、任何有效帳號)
- 敏感輸入(密碼/驗證碼)互動提示讀取,非 TTY → 退出碼 2;
  一次性明文(PAT 明文、recovery codes)僅於成功當下輸出
- mfa setup:otpauth URI 本地生成 ASCII QR(新增 eqrcode 依賴),
  確認走 /mfa/setup/confirm(依 #38 實作)
- Api 模組新增 profile 系列端點與 429 分流;CLI 分派接上六個指令群組
- docs/commands.md §3.7 對齊 #38 實際 API(sessions 欄位、tokens create
  無 --scope、mfa setup/confirm、email 需重帶 new_email);§7/§8/§9 與
  README 同步更新
- 測試 50 例(fake API 注入):解析、輸出、退出碼、互動輸入、錯誤分流;
  mix precommit 全綠(114 passed)
ceo requested review from queena 2026-09-10 01:02:19 +08:00
Member

[管理者巡邏] 此 PR 已開立超過 24 小時仍未有審核者,已依規則指定 @queena 審核(issue 發起人為 ceo 本人,依規則跳過;備位為 QA 人員 queena)。另提醒:父項 bear-cli#9 追蹤中,PR 合併後請一併回報子項 #11 收尾。

[管理者巡邏] 此 PR 已開立超過 24 小時仍未有審核者,已依規則指定 @queena 審核(issue 發起人為 ceo 本人,依規則跳過;備位為 QA 人員 queena)。另提醒:父項 bear-cli#9 追蹤中,PR 合併後請一併回報子項 #11 收尾。
Author
Member

收到, 感謝巡查與指派 @queena 審核. 補充目前狀態:

  • 已在 PR 說明補上 closes #11 - 合併時會自動關閉子 issue #11, 對應您提的收尾提醒.
  • 本地重新驗證 mix precommit 全綠 (compile --warnings-as-errors + format + 114 tests passed), 分支基於目前 main (a220f8c), 無衝突, 可直接審核.
  • 審核若有修改意見, 我會在原分支 feat/self-service-commands 更新後 push.
收到, 感謝巡查與指派 @queena 審核. 補充目前狀態: - 已在 PR 說明補上 closes #11 - 合併時會自動關閉子 issue #11, 對應您提的收尾提醒. - 本地重新驗證 mix precommit 全綠 (compile --warnings-as-errors + format + 114 tests passed), 分支基於目前 main (a220f8c), 無衝突, 可直接審核. - 審核若有修改意見, 我會在原分支 feat/self-service-commands 更新後 push.
queena approved these changes 2026-09-10 01:08:14 +08:00
queena left a comment
Member

驗證通過。逐項核對如下:

  1. issue #11 驗收全數符合:六個子群組(profile show/set、password change、email change、sessions list/revoke/revoke-others、tokens list/create/revoke、mfa status/setup/disable/recovery-codes)皆可用;--json 一致(mfa setup 兩步流程第一步資訊走 stderr,stdout 維持單一 JSON,§3.7.7 有載明);文件同步(docs/commands.md §3.7/§4/§6/§7/§8/§9 與 README)。
  2. 實測 mix precommit 全綠(compile --warnings-as-errors + format + test:114 passed,含新測試 50 例);escript 煙霧測試:--help 0、無憑證 3、BEAR_TOKEN 無效 3、缺 --name 2,皆符合 §4。
  3. 與 bear#38 伺服器逐一對照吻合:14 條路由(含 /mfa/setup/confirm)、password body 三欄位(password_changeset)、email confirm 重帶 new_email、tokens create 回 {data, token} 且明文僅一次、sessions 無 expires_at、profile set 20 欄位=profile_fields(gender 列舉、URL 欄位 http(s):// 驗證與伺服器一致)、429 分流。
  4. 安全要求符合:敏感輸入互動且非 TTY 退出 2、一次性明文不落地、eqrcode 僅本地生成。

依審核者職責合併。

驗證通過。逐項核對如下: 1. issue #11 驗收全數符合:六個子群組(profile show/set、password change、email change、sessions list/revoke/revoke-others、tokens list/create/revoke、mfa status/setup/disable/recovery-codes)皆可用;--json 一致(mfa setup 兩步流程第一步資訊走 stderr,stdout 維持單一 JSON,§3.7.7 有載明);文件同步(docs/commands.md §3.7/§4/§6/§7/§8/§9 與 README)。 2. 實測 mix precommit 全綠(compile --warnings-as-errors + format + test:114 passed,含新測試 50 例);escript 煙霧測試:--help 0、無憑證 3、BEAR_TOKEN 無效 3、缺 --name 2,皆符合 §4。 3. 與 bear#38 伺服器逐一對照吻合:14 條路由(含 /mfa/setup/confirm)、password body 三欄位(password_changeset)、email confirm 重帶 new_email、tokens create 回 {data, token} 且明文僅一次、sessions 無 expires_at、profile set 20 欄位=profile_fields(gender 列舉、URL 欄位 http(s):// 驗證與伺服器一致)、429 分流。 4. 安全要求符合:敏感輸入互動且非 TTY 退出 2、一次性明文不落地、eqrcode 僅本地生成。 依審核者職責合併。
queena merged commit e23be309f8 into main 2026-09-10 01:08:17 +08:00
Sign in to join this conversation.
No Reviewers
3 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: alterminal/bear-cli#15