Skip to content

Implement loopback OAuth login for the ns-upgrade CLI #5

Description

@GroophyLifefor

Tasks

  • 1.1 Implement the loopback callback server (port scan 8765-8770, bind, state validation, styled success page, timeout, stderr URL fallback) and verify unit tests for successful callback, state mismatch, timeout, and port exhaustion pass
  • 1.2 Build the sign-in URL (extension=nsolid-plugin&port&state), open the browser, and verify the URL/query construction tests pass
  • 1.3 Verify no code path persists credentials (assert no credential files or env writes across the login and submission tests)

Flow

sequenceDiagram
    autonumber
    actor U as User
    participant CLI as ns-upgrade CLI
    participant ACC as Accounts UI

    CLI->>CLI: Start loopback server on 127.0.0.1<br/>first free port in 8765-8770
    CLI->>CLI: Generate CSRF state
    CLI->>ACC: Open {accountsUrl}/sign-in?extension=nsolid-plugin&port={port}&state={state}

    Note over ACC: Multi-org user picks an organization<br/>Org-less user gets one created

    ACC-->>CLI: Redirect to http://127.0.0.1:{port}/callback<br/>with org token + orgId
    CLI->>CLI: Validate state and keep token in memory only
    CLI-->>U: Show styled success page
Loading

Expectation

  • Every scan submission is preceded by a completed login; the session is used only within the invocation that created it.
  • No token, session, or password is ever written to files, environment, or platform credential stores — successful or not.
  • A callback whose state does not match is rejected and the CLI keeps waiting; a timeout is reported if no callback arrives within the window.
  • When every port in 8765-8770 is in use, the CLI reports the failure and offers no silent retry.
  • When the environment cannot open a browser, the CLI prints the sign-in URL to the terminal so the user can complete the login manually.
  • A declined or aborted login stops the run: no scan data is submitted.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions