Compare commits
2 Commits
a8a1614019
...
fix/gatewa
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ca214ccc76 | ||
| 4ebce3422d |
@@ -23,6 +23,7 @@
|
|||||||
},
|
},
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@mosaicstack/db": "workspace:*",
|
"@mosaicstack/db": "workspace:*",
|
||||||
|
"commander": "^13.0.0",
|
||||||
"drizzle-orm": "^0.45.1"
|
"drizzle-orm": "^0.45.1"
|
||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
|
|||||||
68
packages/log/src/cli.spec.ts
Normal file
68
packages/log/src/cli.spec.ts
Normal file
@@ -0,0 +1,68 @@
|
|||||||
|
import { Command } from 'commander';
|
||||||
|
import { describe, it, expect } from 'vitest';
|
||||||
|
|
||||||
|
import { registerLogCommand } from './cli.js';
|
||||||
|
|
||||||
|
function buildTestProgram(): Command {
|
||||||
|
const program = new Command('mosaic');
|
||||||
|
program.exitOverride(); // prevent process.exit in tests
|
||||||
|
registerLogCommand(program);
|
||||||
|
return program;
|
||||||
|
}
|
||||||
|
|
||||||
|
describe('registerLogCommand', () => {
|
||||||
|
it('registers a "log" subcommand on the parent', () => {
|
||||||
|
const program = buildTestProgram();
|
||||||
|
const names = program.commands.map((c) => c.name());
|
||||||
|
expect(names).toContain('log');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('log command has tail, search, export, and level subcommands', () => {
|
||||||
|
const program = buildTestProgram();
|
||||||
|
const logCmd = program.commands.find((c) => c.name() === 'log');
|
||||||
|
expect(logCmd).toBeDefined();
|
||||||
|
const subNames = logCmd!.commands.map((c) => c.name());
|
||||||
|
expect(subNames).toContain('tail');
|
||||||
|
expect(subNames).toContain('search');
|
||||||
|
expect(subNames).toContain('export');
|
||||||
|
expect(subNames).toContain('level');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('tail subcommand has expected options', () => {
|
||||||
|
const program = buildTestProgram();
|
||||||
|
const logCmd = program.commands.find((c) => c.name() === 'log')!;
|
||||||
|
const tailCmd = logCmd.commands.find((c) => c.name() === 'tail')!;
|
||||||
|
const optionNames = tailCmd.options.map((o) => o.long);
|
||||||
|
expect(optionNames).toContain('--agent');
|
||||||
|
expect(optionNames).toContain('--level');
|
||||||
|
expect(optionNames).toContain('--category');
|
||||||
|
expect(optionNames).toContain('--tier');
|
||||||
|
expect(optionNames).toContain('--limit');
|
||||||
|
expect(optionNames).toContain('--db');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('search subcommand accepts a positional query argument', () => {
|
||||||
|
const program = buildTestProgram();
|
||||||
|
const logCmd = program.commands.find((c) => c.name() === 'log')!;
|
||||||
|
const searchCmd = logCmd.commands.find((c) => c.name() === 'search')!;
|
||||||
|
// Commander stores positional args in _args
|
||||||
|
const argNames = searchCmd.registeredArguments.map((a) => a.name());
|
||||||
|
expect(argNames).toContain('query');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('export subcommand accepts a positional path argument', () => {
|
||||||
|
const program = buildTestProgram();
|
||||||
|
const logCmd = program.commands.find((c) => c.name() === 'log')!;
|
||||||
|
const exportCmd = logCmd.commands.find((c) => c.name() === 'export')!;
|
||||||
|
const argNames = exportCmd.registeredArguments.map((a) => a.name());
|
||||||
|
expect(argNames).toContain('path');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('level subcommand accepts a positional level argument', () => {
|
||||||
|
const program = buildTestProgram();
|
||||||
|
const logCmd = program.commands.find((c) => c.name() === 'log')!;
|
||||||
|
const levelCmd = logCmd.commands.find((c) => c.name() === 'level')!;
|
||||||
|
const argNames = levelCmd.registeredArguments.map((a) => a.name());
|
||||||
|
expect(argNames).toContain('level');
|
||||||
|
});
|
||||||
|
});
|
||||||
177
packages/log/src/cli.ts
Normal file
177
packages/log/src/cli.ts
Normal file
@@ -0,0 +1,177 @@
|
|||||||
|
import { writeFileSync } from 'node:fs';
|
||||||
|
|
||||||
|
import type { Command } from 'commander';
|
||||||
|
|
||||||
|
import type { LogCategory, LogLevel, LogTier } from './agent-logs.js';
|
||||||
|
|
||||||
|
interface FilterOptions {
|
||||||
|
agent?: string;
|
||||||
|
level?: string;
|
||||||
|
category?: string;
|
||||||
|
tier?: string;
|
||||||
|
limit?: string;
|
||||||
|
db?: string;
|
||||||
|
}
|
||||||
|
|
||||||
|
function parseLimit(raw: string | undefined, defaultVal = 50): number {
|
||||||
|
if (!raw) return defaultVal;
|
||||||
|
const n = parseInt(raw, 10);
|
||||||
|
return Number.isFinite(n) && n > 0 ? n : defaultVal;
|
||||||
|
}
|
||||||
|
|
||||||
|
function buildQuery(opts: FilterOptions) {
|
||||||
|
return {
|
||||||
|
...(opts.agent ? { sessionId: opts.agent } : {}),
|
||||||
|
...(opts.level ? { level: opts.level as LogLevel } : {}),
|
||||||
|
...(opts.category ? { category: opts.category as LogCategory } : {}),
|
||||||
|
...(opts.tier ? { tier: opts.tier as LogTier } : {}),
|
||||||
|
limit: parseLimit(opts.limit),
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
async function openDb(connectionString: string) {
|
||||||
|
const { createDb } = await import('@mosaicstack/db');
|
||||||
|
return createDb(connectionString);
|
||||||
|
}
|
||||||
|
|
||||||
|
function resolveConnectionString(opts: FilterOptions): string | undefined {
|
||||||
|
return opts.db ?? process.env['DATABASE_URL'];
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Register log subcommands on an existing Commander program.
|
||||||
|
* This avoids cross-package Commander version mismatches by using the
|
||||||
|
* caller's Command instance directly.
|
||||||
|
*/
|
||||||
|
export function registerLogCommand(parent: Command): void {
|
||||||
|
const log = parent.command('log').description('Query and manage agent logs');
|
||||||
|
|
||||||
|
// ─── tail ───────────────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
log
|
||||||
|
.command('tail')
|
||||||
|
.description('Tail recent agent logs')
|
||||||
|
.option('--agent <id>', 'Filter by agent/session ID')
|
||||||
|
.option('--level <level>', 'Filter by log level (debug|info|warn|error)')
|
||||||
|
.option('--category <cat>', 'Filter by category (decision|tool_use|learning|error|general)')
|
||||||
|
.option('--tier <tier>', 'Filter by tier (hot|warm|cold)')
|
||||||
|
.option('--limit <n>', 'Number of logs to return (default 50)', '50')
|
||||||
|
.option('--db <connection-string>', 'Database connection string (or set DATABASE_URL)')
|
||||||
|
.action(async (opts: FilterOptions) => {
|
||||||
|
const connStr = resolveConnectionString(opts);
|
||||||
|
if (!connStr) {
|
||||||
|
console.error('Database connection required: use --db or set DATABASE_URL');
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
|
||||||
|
const handle = await openDb(connStr);
|
||||||
|
try {
|
||||||
|
const { createLogService } = await import('./log-service.js');
|
||||||
|
const svc = createLogService(handle.db);
|
||||||
|
const query = buildQuery(opts);
|
||||||
|
|
||||||
|
const logs = await svc.logs.query(query);
|
||||||
|
if (logs.length === 0) {
|
||||||
|
console.log('No logs found.');
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
for (const entry of logs) {
|
||||||
|
const ts = new Date(entry.createdAt).toISOString();
|
||||||
|
console.log(`[${ts}] [${entry.level}] [${entry.category}] ${entry.content}`);
|
||||||
|
}
|
||||||
|
} finally {
|
||||||
|
await handle.close();
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
// ─── search ─────────────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
log
|
||||||
|
.command('search <query>')
|
||||||
|
.description('Full-text search over agent logs')
|
||||||
|
.option('--agent <id>', 'Filter by agent/session ID')
|
||||||
|
.option('--level <level>', 'Filter by log level (debug|info|warn|error)')
|
||||||
|
.option('--category <cat>', 'Filter by category (decision|tool_use|learning|error|general)')
|
||||||
|
.option('--tier <tier>', 'Filter by tier (hot|warm|cold)')
|
||||||
|
.option('--limit <n>', 'Number of logs to return (default 50)', '50')
|
||||||
|
.option('--db <connection-string>', 'Database connection string (or set DATABASE_URL)')
|
||||||
|
.action(async (query: string, opts: FilterOptions) => {
|
||||||
|
const connStr = resolveConnectionString(opts);
|
||||||
|
if (!connStr) {
|
||||||
|
console.error('Database connection required: use --db or set DATABASE_URL');
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
|
||||||
|
const handle = await openDb(connStr);
|
||||||
|
try {
|
||||||
|
const { createLogService } = await import('./log-service.js');
|
||||||
|
const svc = createLogService(handle.db);
|
||||||
|
const baseQuery = buildQuery(opts);
|
||||||
|
|
||||||
|
const logs = await svc.logs.query(baseQuery);
|
||||||
|
const lowerQ = query.toLowerCase();
|
||||||
|
const matched = logs.filter(
|
||||||
|
(e) =>
|
||||||
|
e.content.toLowerCase().includes(lowerQ) ||
|
||||||
|
(e.metadata != null && JSON.stringify(e.metadata).toLowerCase().includes(lowerQ)),
|
||||||
|
);
|
||||||
|
|
||||||
|
if (matched.length === 0) {
|
||||||
|
console.log('No matching logs found.');
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
for (const entry of matched) {
|
||||||
|
const ts = new Date(entry.createdAt).toISOString();
|
||||||
|
console.log(`[${ts}] [${entry.level}] [${entry.category}] ${entry.content}`);
|
||||||
|
}
|
||||||
|
} finally {
|
||||||
|
await handle.close();
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
// ─── export ─────────────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
log
|
||||||
|
.command('export <path>')
|
||||||
|
.description('Export matching logs to an NDJSON file')
|
||||||
|
.option('--agent <id>', 'Filter by agent/session ID')
|
||||||
|
.option('--level <level>', 'Filter by log level (debug|info|warn|error)')
|
||||||
|
.option('--category <cat>', 'Filter by category (decision|tool_use|learning|error|general)')
|
||||||
|
.option('--tier <tier>', 'Filter by tier (hot|warm|cold)')
|
||||||
|
.option('--limit <n>', 'Number of logs to export (default 50)', '50')
|
||||||
|
.option('--db <connection-string>', 'Database connection string (or set DATABASE_URL)')
|
||||||
|
.action(async (outputPath: string, opts: FilterOptions) => {
|
||||||
|
const connStr = resolveConnectionString(opts);
|
||||||
|
if (!connStr) {
|
||||||
|
console.error('Database connection required: use --db or set DATABASE_URL');
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
|
||||||
|
const handle = await openDb(connStr);
|
||||||
|
try {
|
||||||
|
const { createLogService } = await import('./log-service.js');
|
||||||
|
const svc = createLogService(handle.db);
|
||||||
|
const query = buildQuery(opts);
|
||||||
|
|
||||||
|
const logs = await svc.logs.query(query);
|
||||||
|
const ndjson = logs.map((e) => JSON.stringify(e)).join('\n');
|
||||||
|
writeFileSync(outputPath, ndjson, 'utf8');
|
||||||
|
console.log(`Exported ${logs.length} log(s) to ${outputPath}`);
|
||||||
|
} finally {
|
||||||
|
await handle.close();
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
// ─── level ──────────────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
log
|
||||||
|
.command('level <level>')
|
||||||
|
.description('Set runtime log level for the connected log service')
|
||||||
|
.action((level: string) => {
|
||||||
|
void level;
|
||||||
|
console.log(
|
||||||
|
'Runtime log level adjustment is not supported in current mode (DB-backed log service).',
|
||||||
|
);
|
||||||
|
process.exitCode = 0;
|
||||||
|
});
|
||||||
|
}
|
||||||
@@ -9,3 +9,4 @@ export {
|
|||||||
type LogTier,
|
type LogTier,
|
||||||
type LogQuery,
|
type LogQuery,
|
||||||
} from './agent-logs.js';
|
} from './agent-logs.js';
|
||||||
|
export { registerLogCommand } from './cli.js';
|
||||||
|
|||||||
@@ -30,6 +30,7 @@
|
|||||||
"@mosaicstack/brain": "workspace:*",
|
"@mosaicstack/brain": "workspace:*",
|
||||||
"@mosaicstack/config": "workspace:*",
|
"@mosaicstack/config": "workspace:*",
|
||||||
"@mosaicstack/forge": "workspace:*",
|
"@mosaicstack/forge": "workspace:*",
|
||||||
|
"@mosaicstack/log": "workspace:*",
|
||||||
"@mosaicstack/macp": "workspace:*",
|
"@mosaicstack/macp": "workspace:*",
|
||||||
"@mosaicstack/memory": "workspace:*",
|
"@mosaicstack/memory": "workspace:*",
|
||||||
"@mosaicstack/prdy": "workspace:*",
|
"@mosaicstack/prdy": "workspace:*",
|
||||||
|
|||||||
@@ -74,7 +74,8 @@ export function saveSession(gatewayUrl: string, auth: AuthResult): void {
|
|||||||
expiresAt: new Date(Date.now() + 7 * 24 * 60 * 60 * 1000).toISOString(), // 7 days
|
expiresAt: new Date(Date.now() + 7 * 24 * 60 * 60 * 1000).toISOString(), // 7 days
|
||||||
};
|
};
|
||||||
|
|
||||||
writeFileSync(SESSION_FILE, JSON.stringify(session, null, 2), 'utf-8');
|
// 0o600: owner read/write only — the session cookie is a credential
|
||||||
|
writeFileSync(SESSION_FILE, JSON.stringify(session, null, 2), { encoding: 'utf-8', mode: 0o600 });
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|||||||
@@ -3,6 +3,7 @@
|
|||||||
import { createRequire } from 'module';
|
import { createRequire } from 'module';
|
||||||
import { Command } from 'commander';
|
import { Command } from 'commander';
|
||||||
import { registerBrainCommand } from '@mosaicstack/brain';
|
import { registerBrainCommand } from '@mosaicstack/brain';
|
||||||
|
import { registerLogCommand } from '@mosaicstack/log';
|
||||||
import { registerMemoryCommand } from '@mosaicstack/memory';
|
import { registerMemoryCommand } from '@mosaicstack/memory';
|
||||||
import { registerQualityRails } from '@mosaicstack/quality-rails';
|
import { registerQualityRails } from '@mosaicstack/quality-rails';
|
||||||
import { registerQueueCommand } from '@mosaicstack/queue';
|
import { registerQueueCommand } from '@mosaicstack/queue';
|
||||||
@@ -350,6 +351,10 @@ registerBrainCommand(program);
|
|||||||
|
|
||||||
registerQualityRails(program);
|
registerQualityRails(program);
|
||||||
|
|
||||||
|
// ─── log ─────────────────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
registerLogCommand(program);
|
||||||
|
|
||||||
// ─── memory ──────────────────────────────────────────────────────────────
|
// ─── memory ──────────────────────────────────────────────────────────────
|
||||||
|
|
||||||
registerMemoryCommand(program);
|
registerMemoryCommand(program);
|
||||||
|
|||||||
@@ -126,10 +126,18 @@ export function registerGatewayCommand(program: Command): void {
|
|||||||
.description('Sign in to the gateway (defaults to URL from meta.json)')
|
.description('Sign in to the gateway (defaults to URL from meta.json)')
|
||||||
.option('-g, --gateway <url>', 'Gateway URL (overrides meta.json)')
|
.option('-g, --gateway <url>', 'Gateway URL (overrides meta.json)')
|
||||||
.option('-e, --email <email>', 'Email address')
|
.option('-e, --email <email>', 'Email address')
|
||||||
.option('-p, --password <password>', 'Password')
|
.option(
|
||||||
|
'-p, --password <password>',
|
||||||
|
'[UNSAFE] Avoid — exposes credentials in shell history and process listings',
|
||||||
|
)
|
||||||
.action(async (cmdOpts: { gateway?: string; email?: string; password?: string }) => {
|
.action(async (cmdOpts: { gateway?: string; email?: string; password?: string }) => {
|
||||||
const { runLogin } = await import('./gateway/login.js');
|
const { runLogin } = await import('./gateway/login.js');
|
||||||
const url = getGatewayUrl(cmdOpts.gateway);
|
const url = getGatewayUrl(cmdOpts.gateway);
|
||||||
|
if (cmdOpts.password) {
|
||||||
|
console.warn(
|
||||||
|
'Warning: --password flag exposes credentials in shell history and process listings.',
|
||||||
|
);
|
||||||
|
}
|
||||||
try {
|
try {
|
||||||
await runLogin({ gatewayUrl: url, email: cmdOpts.email, password: cmdOpts.password });
|
await runLogin({ gatewayUrl: url, email: cmdOpts.email, password: cmdOpts.password });
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
|
|||||||
@@ -2,6 +2,62 @@ import { createInterface } from 'node:readline';
|
|||||||
import { signIn, saveSession } from '../../auth.js';
|
import { signIn, saveSession } from '../../auth.js';
|
||||||
import { readMeta } from './daemon.js';
|
import { readMeta } from './daemon.js';
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Prompt for a single line of input (with echo).
|
||||||
|
*/
|
||||||
|
export function promptLine(question: string): Promise<string> {
|
||||||
|
const rl = createInterface({ input: process.stdin, output: process.stdout });
|
||||||
|
return new Promise((resolve) => {
|
||||||
|
rl.question(question, (answer) => {
|
||||||
|
rl.close();
|
||||||
|
resolve(answer.trim());
|
||||||
|
});
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Prompt for a secret value without echoing the typed characters to the terminal.
|
||||||
|
* Uses TTY raw mode when available so that passwords do not appear in terminal
|
||||||
|
* recordings, scrollback, or shared screen sessions.
|
||||||
|
*/
|
||||||
|
export function promptSecret(question: string): Promise<string> {
|
||||||
|
return new Promise((resolve) => {
|
||||||
|
process.stdout.write(question);
|
||||||
|
if (process.stdin.isTTY) {
|
||||||
|
process.stdin.setRawMode(true);
|
||||||
|
}
|
||||||
|
process.stdin.resume();
|
||||||
|
process.stdin.setEncoding('utf-8');
|
||||||
|
|
||||||
|
let secret = '';
|
||||||
|
const onData = (char: string): void => {
|
||||||
|
if (char === '\n' || char === '\r' || char === '\u0004') {
|
||||||
|
process.stdout.write('\n');
|
||||||
|
if (process.stdin.isTTY) {
|
||||||
|
process.stdin.setRawMode(false);
|
||||||
|
}
|
||||||
|
process.stdin.pause();
|
||||||
|
process.stdin.removeListener('data', onData);
|
||||||
|
resolve(secret);
|
||||||
|
} else if (char === '\u0003') {
|
||||||
|
// ^C
|
||||||
|
process.stdout.write('\n');
|
||||||
|
if (process.stdin.isTTY) {
|
||||||
|
process.stdin.setRawMode(false);
|
||||||
|
}
|
||||||
|
process.stdin.pause();
|
||||||
|
process.stdin.removeListener('data', onData);
|
||||||
|
process.exit(130);
|
||||||
|
} else if (char === '\u007f' || char === '\b') {
|
||||||
|
secret = secret.slice(0, -1);
|
||||||
|
} else {
|
||||||
|
secret += char;
|
||||||
|
}
|
||||||
|
};
|
||||||
|
process.stdin.on('data', onData);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Shared login helper used by both `mosaic login` and `mosaic gateway login`.
|
* Shared login helper used by both `mosaic login` and `mosaic gateway login`.
|
||||||
* Prompts for email/password if not supplied, signs in, and persists the session.
|
* Prompts for email/password if not supplied, signs in, and persists the session.
|
||||||
@@ -11,17 +67,9 @@ export async function runLogin(opts: {
|
|||||||
email?: string;
|
email?: string;
|
||||||
password?: string;
|
password?: string;
|
||||||
}): Promise<void> {
|
}): Promise<void> {
|
||||||
let email = opts.email;
|
const email = opts.email ?? (await promptLine('Email: '));
|
||||||
let password = opts.password;
|
// Do not trim password — it may intentionally contain leading/trailing whitespace
|
||||||
|
const password = opts.password ?? (await promptSecret('Password: '));
|
||||||
if (!email || !password) {
|
|
||||||
const rl = createInterface({ input: process.stdin, output: process.stdout });
|
|
||||||
const ask = (q: string): Promise<string> => new Promise((resolve) => rl.question(q, resolve));
|
|
||||||
|
|
||||||
if (!email) email = await ask('Email: ');
|
|
||||||
if (!password) password = await ask('Password: ');
|
|
||||||
rl.close();
|
|
||||||
}
|
|
||||||
|
|
||||||
const auth = await signIn(opts.gatewayUrl, email, password);
|
const auth = await signIn(opts.gatewayUrl, email, password);
|
||||||
saveSession(opts.gatewayUrl, auth);
|
saveSession(opts.gatewayUrl, auth);
|
||||||
|
|||||||
@@ -16,14 +16,9 @@ vi.mock('./daemon.js', () => ({
|
|||||||
|
|
||||||
vi.mock('./login.js', () => ({
|
vi.mock('./login.js', () => ({
|
||||||
getGatewayUrl: vi.fn().mockReturnValue('http://localhost:14242'),
|
getGatewayUrl: vi.fn().mockReturnValue('http://localhost:14242'),
|
||||||
}));
|
// promptLine/promptSecret are used by ensureSession; return fixed values so tests don't block on stdin
|
||||||
|
promptLine: vi.fn().mockResolvedValue('test@example.com'),
|
||||||
// Mock readline so tests don't block on stdin
|
promptSecret: vi.fn().mockResolvedValue('test-password'),
|
||||||
vi.mock('node:readline', () => ({
|
|
||||||
createInterface: vi.fn().mockReturnValue({
|
|
||||||
question: vi.fn((_q: string, cb: (a: string) => void) => cb('test-input')),
|
|
||||||
close: vi.fn(),
|
|
||||||
}),
|
|
||||||
}));
|
}));
|
||||||
|
|
||||||
const mockFetch = vi.fn();
|
const mockFetch = vi.fn();
|
||||||
|
|||||||
@@ -1,7 +1,6 @@
|
|||||||
import { createInterface } from 'node:readline';
|
|
||||||
import { loadSession, validateSession, signIn, saveSession } from '../../auth.js';
|
import { loadSession, validateSession, signIn, saveSession } from '../../auth.js';
|
||||||
import { readMeta, writeMeta } from './daemon.js';
|
import { readMeta, writeMeta } from './daemon.js';
|
||||||
import { getGatewayUrl } from './login.js';
|
import { getGatewayUrl, promptLine, promptSecret } from './login.js';
|
||||||
|
|
||||||
interface MintedToken {
|
interface MintedToken {
|
||||||
id: string;
|
id: string;
|
||||||
@@ -58,6 +57,9 @@ export async function mintAdminToken(
|
|||||||
|
|
||||||
/**
|
/**
|
||||||
* Persist the new token into meta.json and print the confirmation banner.
|
* Persist the new token into meta.json and print the confirmation banner.
|
||||||
|
*
|
||||||
|
* Emits a warning when the target gateway differs from the locally installed one,
|
||||||
|
* so operators are aware that meta.json may not reflect the intended gateway.
|
||||||
*/
|
*/
|
||||||
export function persistToken(gatewayUrl: string, minted: MintedToken): void {
|
export function persistToken(gatewayUrl: string, minted: MintedToken): void {
|
||||||
const meta = readMeta() ?? {
|
const meta = readMeta() ?? {
|
||||||
@@ -68,6 +70,15 @@ export function persistToken(gatewayUrl: string, minted: MintedToken): void {
|
|||||||
port: parseInt(new URL(gatewayUrl).port || '14242', 10),
|
port: parseInt(new URL(gatewayUrl).port || '14242', 10),
|
||||||
};
|
};
|
||||||
|
|
||||||
|
// Warn when the target gateway does not match the locally installed one
|
||||||
|
const targetHost = new URL(gatewayUrl).hostname;
|
||||||
|
if (targetHost !== meta.host) {
|
||||||
|
console.warn(
|
||||||
|
`Warning: token was minted against ${gatewayUrl} but is being saved to the local` +
|
||||||
|
` meta.json (host: ${meta.host}). Copy the token manually if targeting a remote gateway.`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
writeMeta({ ...meta, adminToken: minted.plaintext });
|
writeMeta({ ...meta, adminToken: minted.plaintext });
|
||||||
|
|
||||||
const preview = `${minted.plaintext.slice(0, 8)}...`;
|
const preview = `${minted.plaintext.slice(0, 8)}...`;
|
||||||
@@ -108,13 +119,10 @@ export async function ensureSession(gatewayUrl: string): Promise<string> {
|
|||||||
console.log(`No session found for ${gatewayUrl}. Please sign in.`);
|
console.log(`No session found for ${gatewayUrl}. Please sign in.`);
|
||||||
}
|
}
|
||||||
|
|
||||||
// Prompt for credentials
|
// Prompt for credentials — password must not be echoed to the terminal
|
||||||
const rl = createInterface({ input: process.stdin, output: process.stdout });
|
const email = await promptLine('Email: ');
|
||||||
const ask = (q: string): Promise<string> => new Promise((resolve) => rl.question(q, resolve));
|
// Do not trim password — it may contain intentional leading/trailing whitespace
|
||||||
|
const password = await promptSecret('Password: ');
|
||||||
const email = (await ask('Email: ')).trim();
|
|
||||||
const password = (await ask('Password: ')).trim();
|
|
||||||
rl.close();
|
|
||||||
|
|
||||||
const auth = await signIn(gatewayUrl, email, password).catch((err: unknown) => {
|
const auth = await signIn(gatewayUrl, email, password).catch((err: unknown) => {
|
||||||
console.error(err instanceof Error ? err.message : String(err));
|
console.error(err instanceof Error ? err.message : String(err));
|
||||||
|
|||||||
6
pnpm-lock.yaml
generated
6
pnpm-lock.yaml
generated
@@ -404,6 +404,9 @@ importers:
|
|||||||
'@mosaicstack/db':
|
'@mosaicstack/db':
|
||||||
specifier: workspace:*
|
specifier: workspace:*
|
||||||
version: link:../db
|
version: link:../db
|
||||||
|
commander:
|
||||||
|
specifier: ^13.0.0
|
||||||
|
version: 13.1.0
|
||||||
drizzle-orm:
|
drizzle-orm:
|
||||||
specifier: ^0.45.1
|
specifier: ^0.45.1
|
||||||
version: 0.45.1(@electric-sql/pglite@0.2.17)(@opentelemetry/api@1.9.0)(@types/better-sqlite3@7.6.13)(@types/pg@8.15.6)(better-sqlite3@12.8.0)(kysely@0.28.11)(postgres@3.4.8)
|
version: 0.45.1(@electric-sql/pglite@0.2.17)(@opentelemetry/api@1.9.0)(@types/better-sqlite3@7.6.13)(@types/pg@8.15.6)(better-sqlite3@12.8.0)(kysely@0.28.11)(postgres@3.4.8)
|
||||||
@@ -469,6 +472,9 @@ importers:
|
|||||||
'@mosaicstack/forge':
|
'@mosaicstack/forge':
|
||||||
specifier: workspace:*
|
specifier: workspace:*
|
||||||
version: link:../forge
|
version: link:../forge
|
||||||
|
'@mosaicstack/log':
|
||||||
|
specifier: workspace:*
|
||||||
|
version: link:../log
|
||||||
'@mosaicstack/macp':
|
'@mosaicstack/macp':
|
||||||
specifier: workspace:*
|
specifier: workspace:*
|
||||||
version: link:../macp
|
version: link:../macp
|
||||||
|
|||||||
Reference in New Issue
Block a user