feat(data-app)!: copy the password instead of printing it, also after create/deploy --wait (CLI-23) - #813
Conversation
… create/deploy --wait (CLI-23)
keboola-pr-reviewer-bot
left a comment
There was a problem hiding this comment.
reviewer could not complete: reviewer model call errored (subtype=success, api_status=400) after 1/18 turn(s).
Retry with @keboola-pr-reviewer review once the underlying issue clears.
|
@keboola-pr-reviewer review |
keboola-pr-reviewer-bot
left a comment
There was a problem hiding this comment.
reviewer could not complete: reviewer model call errored (subtype=success, api_status=400) after 1/18 turn(s).
Retry with @keboola-pr-reviewer review once the underlying issue clears.
zajca
left a comment
There was a problem hiding this comment.
Actionable findings from the automated review.
…eploy read the password (CLI-23)
zajca
left a comment
There was a problem hiding this comment.
No actionable findings were found by the automated review.
BREAKING:
kbagent data-app passworddoes not print the password by default any more. A script that reads.data.passwordmust add--reveal, and a REST client must passreveal=true. The command no longer uses a Manage API token (KBC_MANAGE_API_TOKEN,--allow-env-manage-token).What was wrong
data-app passwordrequired a Manage API token, although the password endpoint of sandboxes-service (GET /apps/{appId}/password) accepts any Storage token of the app's project, and the Keboola UI uses the same call. Under an AI agent there is no terminal for the hidden token prompt, so the command failed unless the user exported the Manage token.--json. When an AI agent runs kbagent, the password went into the model context and into the chat history.What changed
data-app passworduses the project token (static or session).ui_url(the app page in the Keboola UI, which shows the password under "Open App") and "Press c to copy the password, Enter to finish". The password goes to the OS clipboard only when the user pressesc, and it is never printed. The prompt shows only for a process in the foreground and ends after 120 seconds.--json, only--copycopies the password. Without--copythe result haspassword_delivered_to: nulland points toui_url.--revealprints the password, as before this change.--copyand--revealtogether areINVALID_ARGUMENT.--openopens the app in the browser.data-app createanddata-app deploytake the same--copyand--reveal, from one shared definition and one delivery function. They need--wait, because sandboxes-service creates the password while it provisions the app (src/Provisioning/AppProvisioner.php). After a successful--waitin a terminal, the command ends with the same prompt, sodeploy --waiton a password app returns after Enter or the timeout. Without a flag and without a terminal the output does not change and kbagent makes no extra API call. When the password read fails after a successful deploy, the result has a warning and the exit code stays 0. Reading the password stays the operationdata-app.password: when a policy denies it,--copyand--revealoncreateanddeployexit withPERMISSION_DENIEDbefore any API call, and the terminal prompt is skipped.create --dry-runchecks the same flags and shows how the password would be delivered.auth_providers[0].type == "password", the same check as in the UI). Another auth type givesVALIDATION_ERROR, and an app without a password yet givesNOT_FOUND./mnt/c/Windows/System32/clip.exe, also when the Windows PATH is not set in the shell.GET /data-apps/{project}/{app_id}/passwordreturns the metadata and addspasswordonly withreveal=true.c, to offer--copy, to warn before--revealthat the password then goes into the chat history, and never to read the clipboard or ask for the password in the chat.Tests
tests/test_data_app_password.pyruns the real CLI, service and HTTP clients against pytest-httpx, with fakes for the clipboard, the terminal and the browser. A leak test checks on every path that the password is not in stdout, stderr, the DEBUG log or the telemetry event, except with--reveal.cthen Enter,cand Enter in one write, an arrow key, Esc, and Ctrl+C (the terminal mode is restored).X-StorageApi-Token, or the bearer and project headers for a session project, and no Manage token header.make checkpasses.A manual run on a test project confirmed that the password endpoint accepts the project Storage token. Before the merge, please also run
data-app deploy --waiton a password app in a terminal, anddata-app passwordwith a limited Storage token and with a session token.Docs:
gotchas.md(since vNEXT),commands-reference.md,data-app-workflow.md,keboola-expert.md,context.py,CLAUDE.md,docs/TUTORIAL.md,docs/web-server-endpoints.md. No version bump, no changelog entry.Fixes CLI-23