Repository navigation
feat(auth): migrate CLI login to scoped access tokens - #275
Conversation
The dashboard confirm page now mints a `zat_` personal access token instead of the deprecated unscoped `sk-` API key. The callback accepts the new `access_token` form field and falls back to `api_key` so the CLI keeps working against dashboard builds that predate the change. Users still holding a legacy key get a deprecation warning on every authenticated command (suppressed in --json mode), and an interactive `zeabur auth login` re-runs the browser flow instead of reporting "already logged in" so they can migrate in one step. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011g8BAHTy8eMxCcZcw9MDG9
|
Review Council started (round 1). Baseline:
The council is reviewing this pull request; the verdict will follow as a separate comment when the round closes. |
|
CHANGES REQUESTED What This PR DoesMigrates the CLI login flow from legacy How It Works
Findings
Finding Details🟡 F1: Non-interactive already-logged-in legacy path skips the deprecation warningFor a non-interactive Impact is bounded: the classifier is warning-only and never affects authorization (confirmed by rev-codex), and What's Good (🟢)
Baseline Check
Review Metadata
🔴×0 🟡×1 🟢×5 · 💬 Comment |
There was a problem hiding this comment.
Council request_changes — 🔴0 🟡1 🟢5. Reviewed at f7f6f16. Full report: #275 (comment)
…testpackage lint Extract reportExistingLogin so the already-logged-in path also emits the deprecation warning when the stored token is a legacy sk- key. Move the pkg/auth tests to an external package and exercise the callback server end to end instead of the unexported helper. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011g8BAHTy8eMxCcZcw9MDG9
|
@opencodezebra review F1 fixed: extracted |
|
Review Council started (round 2). Baseline:
The council is reviewing this pull request; the verdict will follow as a separate comment when the round closes. |
|
Review Council started (round 2). Baseline:
The council is reviewing this pull request; the verdict will follow as a separate comment when the round closes. |
|
LGTM ✅ — The round-1 finding F1 is fixed and independently verified; no new findings, both reviewers approve. Delta since f7f6f16
Findings
No outstanding or new findings. Finding Details🟡 F1 (Resolved): Non-interactive already-logged-in legacy path skipped the deprecation warningRound 1 found that a non-interactive Verified fixed at head What's Good (🟢)
Baseline Check
Review Metadata
🔴×0 🟡×0 🟢×5 · 💬 Comment |
There was a problem hiding this comment.
Council approve — 🔴0 🟡0 🟢5. Reviewed at 122e69d. Full report: #275 (comment)
Summary
Legacy
sk-API keys are deprecated. This switches the CLI login flow to the new scoped personal access tokens (zat_) issued bycreateAccessToken.The CLI itself never mints a credential: it opens the dashboard confirm page, which mints in the browser session and POSTs back to a localhost callback. The gateway accepts both prefixes as a Bearer token, so the wire format is unchanged. The matching dashboard change is in zeabur/dashboard (confirm page now calls
createAccessTokenand postsaccess_token).Changes
pkg/auth/token.go: token prefix constants,IsLegacyAPIKey, shared deprecation message.pkg/auth/callback.go: readaccess_tokenform field, fall back toapi_keyso the CLI works against dashboard builds that predate the change.pkg/auth/const.go: endpoint renamed toZeaburAccessTokenConfirmEndpoint; URL path unchanged so old CLI builds keep resolving it.auth login: interactive login with a stored legacy key re-runs the browser flow instead of reporting "already logged in". Non-interactive login with a legacyZEABUR_TOKENwarns but proceeds.auth status: warn once per command when the stored token is legacy, suppressed in--jsonmode.Rollout
api_keyfallback.zat_tokens.zeabur auth loginagain.Test plan
go build ./...,go vet,go test ./...zat_zeabur auth statuswith an oldsk-token shows the deprecation warning🤖 Generated with Claude Code
https://claude.ai/code/session_011g8BAHTy8eMxCcZcw9MDG9
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.