Skip to content

fix(setup): preserve saved credential confirmation with real CLI proof - #110

Merged
drewstone merged 12 commits into
mainfrom
fix/cloud-setup-cli-proof-20260929
Sep 29, 2026
Merged

drewstone merged 12 commits into
mainfrom
fix/cloud-setup-cli-proof-20260929

Conversation

@drewstone

@drewstone drewstone commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Result and scope

Follow-up to it-3b54a007f3 after merged #105 and #106. Base: d20628b0bb38ba9e4584bc29f8fa0c9bd7634813. Head: 835c178fc1832e325574a72b8ced2b5a9d0ac621. Main was rechecked at that base. This was the only open Braid PR returned by the final search.

The real CLI exposed a remaining user-facing failure: after successfully saving a newly entered credential, the confirmation said credentials not configured. The wizard had cleared the pending bytes and was rendering the old selection, which did not yet contain the persisted credential reference.

Keep only the successful commit acknowledgement in the existing PreparedCredential helper. Set it after the existing commit callback resolves, then zero and clear the bytes as before. Normal confirmation now says credentials saved securely · value hidden; compact confirmation says cred saved · hidden. Pending and rejected commits cannot render the saved acknowledgement. Existing referenced credentials retain their current presentation.

Production edits are confined to the existing four TUI configuration/credential modules. No configuration writer, schema, canonical profile, connection lifecycle, provider contract, RPC/protocol/controller, fork preview, phase lease, protected speed, dependency, or version change. No deployment, publication, or merge.

Actual CLI proof, committed here

scripts/proof-cloud-setup-cli.mjs is executable source in this PR. It does not depend on the old attachment, construct an application directly, or use --fixture.

Exact-head CLI run and terminal captures: passed on Ubuntu 24.04.5, Node 22.19.0, pnpm 11.24.0. The log records git rev-parse HEAD = 835c178fc1832e325574a72b8ced2b5a9d0ac621.

Commands actually executed:

pnpm install --frozen-lockfile
pnpm build
node scripts/proof-cloud-setup-cli.mjs dist/bin/braid.js
node scripts/proof-cloud-setup-cli.mjs dist/bin/braid.js --compact

Both proof commands exited 0, at 120x40 and 80x24 respectively. Each starts the real CLI executable in a PTY with production encrypted SQLite and a private external database key. It seeds only a pre-existing initial configuration before launch. All subsequent selection changes use keyboard input in the CLI, not JSON edits.

Observed and asserted in each run:

  • Ctrl+K -> Setup -> canonical profile -> Tangle Sandbox -> repository/ref/cwd -> retained files with 1800-second idle expiry -> masked credential -> save.
  • Saved workspace is https://github.com/tangle-network/braid.git, ref main, cwd {base: 'repository', path: 'src'}. Credential reference is persisted without credential bytes in config or terminal captures.
  • Correct saved-credential confirmation. Zero HTTP requests and zero recorded runs at save.
  • Reopen in the same process restores workspace and lifetime. Cancel leaves config bytes unchanged and makes no HTTP request. This CLI case reopens and cancels; it does not type another changed selection before cancellation.
  • A later explicit task submission makes authenticated provider preflight requests and shows the unchanged SERVER_ERROR from the deliberately refusing loopback endpoint.
  • /quit exits 0. A new CLI process reopens the same encrypted storage. Setup selections survive; cancel writes nothing; a later submission uses the reloaded credential. No authentication is injected into that restarted CLI.

The HTTP log contains eight GETs per complete proof, four per explicit submission (/v1/backends, /v1/me, /usage, /subscription), with credentialReceived: true. No credential values are logged.

Current public npm CLI: release gap is still present

The same job separately executed:

npm view @tangle-network/braid dist-tags --json
npm view @tangle-network/braid@latest version dist.integrity gitHead --json
npm install --prefix "$RUNNER_TEMP/braid-cloud-public" @tangle-network/braid@latest
node scripts/proof-cloud-setup-cli.mjs "$RUNNER_TEMP/braid-cloud-public/node_modules/@tangle-network/braid/dist/bin/braid.js" --public-probe

On 2026-09-29 at 08:25 UTC, npm returned latest: 0.3.3. Integrity:

sha512-FpdnL+n8mitEbQWaeKinmZQUmzxwaGN5f+XRTL7vFk6DO4oL4HDFFXo7we5QT0Smr9dqXU/gPyLSXrzdJlmsNw==

The installed public CLI returned --version = 0.3.3. Its actual Ctrl+K screen has Profile, Connection, Runner, Model and Thinking, but no Setup entry. Probe result: setup menu absent, exit 0, no HTTP requests. A successful probe means the observation was recorded, not that public setup works. Main also reports 0.3.3, so version text alone does not identify the merged feature. This PR does not publish a new release or claim the public package contains #105/#106.

Maintained regressions and completed existing checks

All final-head workflows passed.

test/configuration-credential-flow.test.ts extends the existing success case to assert truthful saved status and zeroed bytes at 40 and 80 columns, adds a pending/rejected commit case, and retains the existing Escape/no-commit case. All three cases passed in the full suite.

Existing CI for this head uses GitHub merge candidate 0b8290c6d3241e44267b6c348e3243fb3221b2f3 (this head into the unchanged main). All four jobs completed successfully:

Command/check Actual result
pnpm install --frozen-lockfile Passed
pnpm check Passed: format, lint, typecheck, boundaries and tests
pnpm format:check within check 1267 files checked; 187 TypeScript documentation examples formatted
pnpm lint within check 1267 files checked; passed
pnpm typecheck within check tsc -p tsconfig.json --noEmit passed
pnpm boundaries within check Passed across 667 runtime source files
pnpm test within check Reported TAP groups 1116/1116 and 19/19, zero failures/skips; release-evidence contract self-test also passed
pnpm release:prepare Passed: repeated check, build, smoke, packed-package runtime checks and release gate. Package preparation only, not publication
macOS node scripts/release/storage-smoke-child.mjs "$PWD" "$RUNNER_TEMP/braid-storage-smoke" Passed: {"encryptedStorage":true,"privateFiles":true}
macOS pnpm run test -- --scope security Passed: TAP groups 180/180 and 19/19, zero failures/skips, plus release-evidence contract self-test
node scripts/live-bridge/matrix.mjs Passed on macOS and Windows

Completed verify job, including package preparation.

The first development iteration hit the existing 300-line module guard. It was fixed by keeping credential bookkeeping in the existing credential helper and removing a single-use type alias, not by raising the limit. The final security and full-suite runs pass that guard.

Limits

The proof endpoint is a loopback HTTP 503 preflight refusal, not a live Tangle service. This establishes setup/save/reopen/cancellation/encrypted reload and subsequent authenticated HTTP submission. It does not establish successful cloud task execution, sandbox admission, an execution receipt, or retained file behavior inside a real sandbox. No paid provider call or cloud sandbox was created. The proof does not change an active run; production lifecycle and receipt code are untouched.

Local container execution was unavailable because it had no pnpm/dependencies and direct GitHub/npm resolution failed. All successful execution results above come from the linked GitHub Actions jobs, not from an unexecuted local script.

tangletools
tangletools previously approved these changes Sep 29, 2026

@tangletools tangletools left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — fb8009c5

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-29T08:08:10Z

tangletools
tangletools previously approved these changes Sep 29, 2026

@tangletools tangletools left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — 8498b9e1

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-29T08:13:10Z

tangletools
tangletools previously approved these changes Sep 29, 2026

@tangletools tangletools left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — a3e527c5

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-29T08:14:12Z

tangletools
tangletools previously approved these changes Sep 29, 2026

@tangletools tangletools left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — de9179e7

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-29T08:15:11Z

tangletools
tangletools previously approved these changes Sep 29, 2026

@tangletools tangletools left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — 54f52958

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-29T08:17:10Z

tangletools
tangletools previously approved these changes Sep 29, 2026

@tangletools tangletools left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — 49b10ecd

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-29T08:18:10Z

tangletools
tangletools previously approved these changes Sep 29, 2026

@tangletools tangletools left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — c97497f8

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-29T08:19:11Z

tangletools
tangletools previously approved these changes Sep 29, 2026

@tangletools tangletools left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — 65ecb152

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-29T08:22:10Z

tangletools
tangletools previously approved these changes Sep 29, 2026

@tangletools tangletools left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — 1cac9dc3

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-29T08:23:11Z

@tangletools tangletools left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — 835c178f

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-29T08:25:12Z

@drewstone drewstone changed the title fix(setup): verify cloud setup through the public CLI after #105/#106 fix(setup): preserve saved credential confirmation with real CLI proof Sep 29, 2026
@drewstone
drewstone merged commit 11eed55 into main Sep 29, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants