Files
bear-cli/README.md
T
alex 14edb84a59 docs: 新增 bear CLI 指令規劃(issue #19)
- 建立獨立倉庫 bear-cli,用於實現 bear 的終端機 CLI 客戶端
- README.md:專案簡介、指令總覽、全域選項、憑證與里程碑
- docs/commands.md:完整指令規格(login/whoami/token/logout/status/apps)
  - 沿用 RFC 8628 Device Authorization Grant 方向(見 bear issue #17 設計文件)
  - 定義全域選項、各指令行為、退出碼、設定/憑證檔與安全考量
- 依需求「先規劃指令、暫不實作」,程式碼留待 P2 起各自開 issue 再進行
2026-08-29 17:25:53 +08:00

84 lines
3.5 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# 🐻 Bear CLI
**Bear CLI** 是 [澳特科技](https://alterminal.com)(Alter Technology)單點登入系統 [Bear](https://gitea.alterminal.com/alterminal/bear) 的**終端機(CLI)客戶端**:讓使用者在 Linux 終端機直接以 Bear 帳號登入、查詢身分、取得並續期 Token,作為 SSO 的終端入口。
> **狀態:規劃階段**。本倉庫目前只規劃指令介面(command spec),**尚未實作任何程式碼**。
> 伺服器端採用的 OIDC **Device Authorization Grant(RFC 8628)** 方向,詳見 bear 倉庫的設計文件 `docs/cli-feature-plan.md`(issue #17)。
---
## 為什麼需要 CLI
Bear 目前所有流程都依賴「瀏覽器」:登入 `/login`、儀表板 Launch、Relying Party 走 Authorization Code Flow + PKCE。但**終端機沒有瀏覽器可互動**,無法完成 `redirect_uri` 回跳,因此需要一個為「無瀏覽器/輸入受限裝置」設計的登入流程,讓 `bear` 指令也能以 OIDC 身分登入並取用 Token。
---
## 指令總覽
| 指令 | 說明 | 階段 |
|------|------|------|
| `bear login` | 啟動 Device Flow 登入(取得授權碼 → 兌換 Token) | P2 |
| `bear whoami` | 顯示目前登入身分(`GET /userinfo`) | P2 |
| `bear token [--refresh]` | 印出 access token(過期自動 refresh),供 pipe 給其他工具 | P2 |
| `bear logout` | 撤銷 refresh token(`POST /revoke`) | P2 |
| `bear status` | 顯示登入狀態與 token 剩餘效期 | P2 |
| `bear apps` | 列出公開應用(需新增公開應用清單 API) | P3 |
完整指令規格(選項、行為、輸出、退出碼)見 [`docs/commands.md`](docs/commands.md)。
---
## 全域選項
| 選項 | 說明 | 預設 |
|------|------|------|
| `--issuer URL` | Bear(OIDC Provider)位址 | `https://alterminal.com` |
| `--config PATH` | 設定檔路徑 | `~/.config/bear/config.json` |
| `--json` | 機器可讀輸出(JSON) | — |
| `-v, --verbose` | 顯示詳細日誌 | — |
| `-h, --help` | 顯示說明 | — |
| `--version` | 顯示版本 | — |
---
## 登入流程(`bear login`,示意)
```
$ bear login
正在向 https://alterminal.com 註冊裝置...
請在瀏覽器開啟:https://alterminal.com/device
輸入代碼:ABCD-EFGH
(等待授權中...)
已登入:alice@example.com
```
登入後,CLI 將 refresh token 寫入本機憑證檔(0600),access token 僅做短命快取。
---
## 憑證與設定檔
| 檔 | 路徑 | 內容 | 權限 |
|----|------|------|------|
| 設定 | `~/.config/bear/config.json` | `issuer`、`client_id`、`scope` | 0644 |
| 憑證 | `~/.local/state/bear/credentials.json` | `refresh_token`(優先)+快取的 `access_token`/`expires_at` | **0600** |
---
## 里程碑
| 階段 | 內容 |
|------|------|
| **P1 伺服器:Device Flow** | `device_codes` 資料表、`POST /device_authorization`、`GET/POST /device` 授權頁、token 端點 `device_code` grant、Discovery 更新(於 bear 倉庫) |
| **P2 CLI 登入** | 本倉庫實作 `login`/`whoami`/`token`/`logout`/`status`、憑證儲存 0600 |
| **P3 進階** | `bear apps`(公開應用清單 API)、QR 顯示、系統 keyring、發行二進位 |
---
## 技術方向(規劃)
- **語言**:Elixir(與 Bear 主專案一致),HTTP 一律使用 `Req`。
- **發行**:`mix escript`(單檔可執行)或 `mix release` 自包含二進位(待定)。
- **安全**:device_code 只存 SHA-256 雜湊、user_code 限流、憑證檔 0600、token 一律不入 log/commit。