Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
66 commits
Select commit Hold shift + click to select a range
9cf2431
CLI: Update SDK to 0a28735 and add org entitlements command
kernel-internal[bot] Aug 17, 2026
dfdba4f
CLI: Update Go SDK to v0.92.0 (a156820)
kernel-internal[bot] Aug 17, 2026
6412b6f
Merge main into cli-coverage-update
kernel-internal[bot] Aug 18, 2026
8a7b363
CLI: Update Go SDK to 6e62bf5 and track managed-auth field reason
kernel-internal[bot] Aug 18, 2026
055d6a9
Merge main into cli-coverage-update
kernel-internal[bot] Aug 19, 2026
ca46838
CLI: Update Go SDK to 796d424 and bind canonical submits to interactions
kernel-internal[bot] Aug 19, 2026
31d2462
CLI: Update Go SDK to 467fea7
kernel-internal[bot] Aug 19, 2026
16880f4
CLI: Update Go SDK to v0.93.0 (0802326)
kernel-internal[bot] Aug 20, 2026
f9b126f
CLI: Update Go SDK to 9a36566 and cover the telemetry control/platfor…
kernel-internal[bot] Aug 21, 2026
063d7f5
CLI: Update Go SDK to c042837 and drop the telemetry control/platform…
kernel-internal[bot] Aug 21, 2026
f777871
Merge main into cli-coverage-update
kernel-internal[bot] Aug 24, 2026
484e19f
CLI: Update Go SDK to 5e48c58 and restore the telemetry control/platf…
kernel-internal[bot] Aug 24, 2026
76455e6
Merge main into cli-coverage-update
kernel-internal[bot] Aug 24, 2026
8b5a06b
CLI: Update Go SDK to 26309b6 and drop the telemetry control/platform…
kernel-internal[bot] Aug 24, 2026
c6c402b
CLI: Update Go SDK to 9de3679 (v0.94.0) and restore the telemetry con…
kernel-internal[bot] Aug 24, 2026
ee72f2d
CLI: Update Go SDK to c472a30
kernel-internal[bot] Aug 26, 2026
cb4630d
Merge main into cli-coverage-update
kernel-internal[bot] Aug 26, 2026
99b27bb
feat: update Go SDK to 46978e2 and add ap-southeast region
kernel-internal[bot] Aug 26, 2026
3ce0c81
chore: update Go SDK to v0.95.0 (0c36fa4)
kernel-internal[bot] Aug 26, 2026
992e0f8
Merge main into cli-coverage-update
kernel-internal[bot] Aug 26, 2026
11fa9ed
chore: update Go SDK to d348ffc and repair merge fallout
kernel-internal[bot] Aug 27, 2026
3ce899d
chore: update Go SDK to v0.96.0 (bb4371c)
kernel-internal[bot] Aug 27, 2026
69e922f
Merge main into cli-coverage-update
kernel-internal[bot] Aug 28, 2026
77bddae
chore: update Go SDK to 6e498fb (captcha task and challenge outcomes)
kernel-internal[bot] Aug 28, 2026
aa1b67c
chore: update Go SDK to 94c784a (managed auth reauth reasons)
kernel-internal[bot] Aug 31, 2026
bd99059
chore: update Go SDK to v0.97.0 (e9ee30b)
kernel-internal[bot] Aug 31, 2026
d21ec11
Merge main into cli-coverage-update
kernel-internal[bot] Sep 2, 2026
fc5ba82
chore: update Go SDK to ed434f7 and add browsers webmcp commands
kernel-internal[bot] Sep 2, 2026
36bd0eb
chore: update Go SDK to v0.98.0 (d02140d)
kernel-internal[bot] Sep 2, 2026
073992e
chore: update Go SDK to 7a377c7 and surface OTLP destination delivery…
kernel-internal[bot] Sep 3, 2026
2bc63e8
Merge main into cli-coverage-update
kernel-internal[bot] Sep 4, 2026
75eae00
chore: update Go SDK to 31c5fee and add vaults commands
kernel-internal[bot] Sep 4, 2026
c3ed6f1
chore: update Go SDK to v0.99.0 (b228059), test and document vaults
kernel-internal[bot] Sep 4, 2026
b4ac39e
chore: update Go SDK to 6ec0643 (vault provider errors, no test-mode …
kernel-internal[bot] Sep 4, 2026
669ea71
chore: pin Go SDK to tagged v0.100.0 (07e74ed)
kernel-internal[bot] Sep 4, 2026
09b13b7
Merge main into cli-coverage-update
kernel-internal[bot] Sep 5, 2026
29cc23d
chore: update Go SDK to 4b985af and surface vaults entitlement
kernel-internal[bot] Sep 5, 2026
0632a7a
chore: update Go SDK to 8abbe5e and surface vault limits
kernel-internal[bot] Sep 5, 2026
a16aa97
Merge main into cli-coverage-update
kernel-internal[bot] Sep 8, 2026
a024421
chore: update Go SDK to 78d7845 and drop removed vault limit fields
kernel-internal[bot] Sep 8, 2026
3e19f72
Merge main into cli-coverage-update
kernel-internal[bot] Sep 9, 2026
9d84917
chore: update Go SDK to 19b510c, restore vault limits, fix webmcp merge
kernel-internal[bot] Sep 9, 2026
e50d2cd
chore: update Go SDK to f8ec7e1 and document ISP proxy countries
kernel-internal[bot] Sep 10, 2026
65b4c30
chore: update Go SDK to f3dcf5a and clarify proxy country defaults
kernel-internal[bot] Sep 10, 2026
eed9632
chore: update Go SDK to a65bb49 and surface invocation status reasons
kernel-internal[bot] Sep 10, 2026
34df646
Merge main into cli-coverage-update
kernel-internal[bot] Sep 10, 2026
a5345c2
chore: update Go SDK to f0c6e4b
kernel-internal[bot] Sep 10, 2026
c9d43d6
chore: update Go SDK to e3ea91dfaa854364133b99e1bfe38e788de48dad
kernel-internal[bot] Sep 10, 2026
e776eb9
chore: update Go SDK to 9d9ffcf (revert config registry guidance)
kernel-internal[bot] Sep 10, 2026
2668f0f
chore: update Go SDK to cd47c64 and add vault provider config commands
kernel-internal[bot] Sep 11, 2026
e34ca19
chore: update Go SDK to v0.101.0 (68050bf)
kernel-internal[bot] Sep 11, 2026
4eb79c9
chore: update Go SDK to 86e3d38 (document punctuation key sequences)
kernel-internal[bot] Sep 11, 2026
621a5f3
Merge main into cli-coverage-update
kernel-internal[bot] Sep 11, 2026
d769a08
chore: update Go SDK to b22a63c and fix vault provider config merge f…
kernel-internal[bot] Sep 11, 2026
efbffa9
chore: update Go SDK to 410bbabd and align vault recovery guidance
kernel-internal[bot] Sep 11, 2026
4ade346
chore: update Go SDK to dc39717 (config registry recommendation union)
kernel-internal[bot] Sep 11, 2026
5a762d8
chore: update Go SDK to b4278bb and add vault card fill
kernel-internal[bot] Sep 13, 2026
671581f
chore: update Go SDK to v0.102.0 (a923b20)
kernel-internal[bot] Sep 14, 2026
056a2ac
Merge main into cli-coverage-update
kernel-internal[bot] Sep 14, 2026
6951796
chore: update Go SDK to ec63b01 and add AgentCard prepare_checkout
kernel-internal[bot] Sep 14, 2026
18c313a
chore: update Go SDK to 7c60d81
kernel-internal[bot] Sep 14, 2026
b743dc3
chore: update Go SDK to 2e5c061 and add managed auth --region
kernel-internal[bot] Sep 14, 2026
803688a
chore: update Go SDK to v0.103.0 (1682e8f)
kernel-internal[bot] Sep 14, 2026
ed9924a
chore: update Go SDK to 5839bab and add credential vault items
kernel-internal[bot] Sep 15, 2026
2d3c5a5
chore: update Go SDK to 55c88c0 and render managed auth input modes
kernel-internal[bot] Sep 15, 2026
1950719
chore: update Go SDK to bcf94cc
kernel-internal[bot] Sep 15, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
189 changes: 178 additions & 11 deletions README.md

Large diffs are not rendered by default.

216 changes: 163 additions & 53 deletions cmd/auth_connections.go

Large diffs are not rendered by default.

212 changes: 196 additions & 16 deletions cmd/auth_connections_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -147,14 +147,21 @@ func TestAuthConnectionsGet_PrintsCanonicalInputMetadata(t *testing.T) {
Status: kernel.ManagedAuthStatusNeedsAuth,
FlowStatus: kernel.ManagedAuthFlowStatusInProgress,
FlowStep: kernel.ManagedAuthFlowStepAwaitingInput,
// Canonical fields and choices always arrive with the interaction
// they belong to, which `submit` needs.
InteractionID: "mai_abc123xyz",
Fields: []kernel.ManagedAuthField{
{
ID: "otp",
Label: "One-time code",
Type: "code",
Ref: "totp_code",
Hint: "Enter the code sent to +1 ••• ••• 1234",
Required: true,
ID: "otp",
Label: "One-time code",
Type: "code",
Ref: "totp_code",
// The keyboard hint is independent of the field type, so
// it is shown even though the type is already "code".
InputMode: "numeric",
Hint: "Enter the code sent to +1 ••• ••• 1234",
Reason: "rejected",
Required: true,
},
},
Choices: []kernel.ManagedAuthChoice{
Expand All @@ -181,8 +188,11 @@ func TestAuthConnectionsGet_PrintsCanonicalInputMetadata(t *testing.T) {
require.NoError(t, c.Get(context.Background(), AuthConnectionGetInput{ID: "e0x3vbw4z66kpwny3k5k46tj"}))

out := outBuf.String()
assert.Contains(t, out, `mai_abc123xyz`)
assert.Contains(t, out, `otp (One-time code)`)
assert.Contains(t, out, `code, ref=totp_code, required`)
// The reason tells the user why the field is being asked for: "rejected"
// means a stored credential was refused, so a new value has to replace it.
assert.Contains(t, out, `code, input_mode=numeric, ref=totp_code, required, reason=rejected`)
assert.Contains(t, out, `hint="Enter the code sent to +1 ••• ••• 1234"`)
assert.Contains(t, out, `mfa_sms (Text message)`)
assert.Contains(t, out, `mfa_method, sms, to=+1 ••• ••• 1234`)
Expand Down Expand Up @@ -752,6 +762,71 @@ func TestCreate_BrowserConfig(t *testing.T) {
assert.False(t, browser.Stealth.Value)
}

// Region is part of the connection's browser config: create sets it, update
// moves future sessions, and login overrides it for that login only.
func TestCreate_BrowserRegion(t *testing.T) {
capturePtermOutput(t)
var captured kernel.AuthConnectionNewParams
fake := &FakeAuthConnectionService{
NewFunc: func(ctx context.Context, body kernel.AuthConnectionNewParams, opts ...option.RequestOption) (*kernel.ManagedAuth, error) {
captured = body
return &kernel.ManagedAuth{ID: "auth_1"}, nil
},
}
c := AuthConnectionCmd{svc: fake}
require.NoError(t, c.Create(context.Background(), AuthConnectionCreateInput{
Domain: "example.com",
ProfileName: "prof",
Region: "eu-west",
}))

assert.Equal(t, kernel.ManagedAuthBrowserConfigRegionEuWest, captured.ManagedAuthCreateRequest.Browser.Region)
}

// Region alone is a real change, so it must satisfy update's "at least one
// field" check rather than being dropped.
func TestUpdate_BrowserRegion(t *testing.T) {
capturePtermOutput(t)
var captured kernel.AuthConnectionUpdateParams
fake := &FakeAuthConnectionService{
UpdateFunc: func(ctx context.Context, id string, body kernel.AuthConnectionUpdateParams, opts ...option.RequestOption) (*kernel.ManagedAuth, error) {
captured = body
return &kernel.ManagedAuth{ID: id}, nil
},
}
c := AuthConnectionCmd{svc: fake}
require.NoError(t, c.Update(context.Background(), AuthConnectionUpdateInput{ID: "auth_1", Region: "ap-southeast"}))

assert.Equal(t, kernel.ManagedAuthBrowserConfigRegionApSoutheast, captured.ManagedAuthUpdateRequest.Browser.Region)
}

func TestLogin_BrowserRegion(t *testing.T) {
capturePtermOutput(t)
var captured kernel.AuthConnectionLoginParams
fake := &FakeAuthConnectionService{
LoginFunc: func(ctx context.Context, id string, body kernel.AuthConnectionLoginParams, opts ...option.RequestOption) (*kernel.LoginResponse, error) {
captured = body
return &kernel.LoginResponse{ID: id}, nil
},
}
c := AuthConnectionCmd{svc: fake}
require.NoError(t, c.Login(context.Background(), AuthConnectionLoginInput{ID: "auth_1", Region: "us-east"}))

assert.Equal(t, kernel.ManagedAuthBrowserConfigRegionUsEast, captured.Browser.Region)
}

func TestCreate_InvalidRegionErrors(t *testing.T) {
capturePtermOutput(t)
c := AuthConnectionCmd{svc: &FakeAuthConnectionService{}}

err := c.Create(context.Background(), AuthConnectionCreateInput{
Domain: "example.com", ProfileName: "prof", Region: "mars",
})

require.Error(t, err)
assert.Contains(t, err.Error(), "invalid --region value")
}

func TestLogin_BrowserProxyMode(t *testing.T) {
capturePtermOutput(t)
var captured kernel.AuthConnectionLoginParams
Expand Down Expand Up @@ -820,16 +895,24 @@ func TestLogin_TelemetryOverride(t *testing.T) {
assert.True(t, captured.Browser.Telemetry.Browser.Screenshot.Enabled.Value)
}

func TestSubmit_CanonicalChoiceID(t *testing.T) {
capturePtermOutput(t)
var captured kernel.AuthConnectionSubmitParams
fake := &FakeAuthConnectionService{
// canonicalSubmitFake serves the current interaction ID from `get` and captures
// what `submit` sends, which is what every canonical submission needs.
func canonicalSubmitFake(interactionID string, captured *kernel.AuthConnectionSubmitParams) *FakeAuthConnectionService {
return &FakeAuthConnectionService{
GetFunc: func(ctx context.Context, id string, opts ...option.RequestOption) (*kernel.ManagedAuth, error) {
return &kernel.ManagedAuth{ID: id, InteractionID: interactionID}, nil
},
SubmitFunc: func(ctx context.Context, id string, body kernel.AuthConnectionSubmitParams, opts ...option.RequestOption) (*kernel.SubmitFieldsResponse, error) {
captured = body
*captured = body
return &kernel.SubmitFieldsResponse{Accepted: true}, nil
},
}
c := AuthConnectionCmd{svc: fake}
}

func TestSubmit_CanonicalChoiceID(t *testing.T) {
capturePtermOutput(t)
var captured kernel.AuthConnectionSubmitParams
c := AuthConnectionCmd{svc: canonicalSubmitFake("mai_current", &captured)}
require.NoError(t, c.Submit(context.Background(), AuthConnectionSubmitInput{
ID: "auth_1",
SelectedChoiceID: "choice_sms",
Expand All @@ -841,6 +924,53 @@ func TestSubmit_CanonicalChoiceID(t *testing.T) {
}

func TestSubmit_CanonicalFieldValues(t *testing.T) {
capturePtermOutput(t)
var captured kernel.AuthConnectionSubmitParams
c := AuthConnectionCmd{svc: canonicalSubmitFake("mai_current", &captured)}
require.NoError(t, c.Submit(context.Background(), AuthConnectionSubmitInput{
ID: "auth_1",
CanonicalFieldValues: map[string]string{"field_email": "me@example.com"},
}))
assert.Equal(t, map[string]string{"field_email": "me@example.com"}, captured.SubmitFieldsRequest.FieldValues)
assert.Nil(t, captured.SubmitFieldsRequest.Fields)
}

func TestSubmit_CanonicalResolvesCurrentInteractionID(t *testing.T) {
capturePtermOutput(t)
var captured kernel.AuthConnectionSubmitParams
c := AuthConnectionCmd{svc: canonicalSubmitFake("mai_current", &captured)}
require.NoError(t, c.Submit(context.Background(), AuthConnectionSubmitInput{
ID: "auth_1",
CanonicalFieldValues: map[string]string{"field_email": "me@example.com"},
}))
require.True(t, captured.SubmitFieldsRequest.InteractionID.Valid())
assert.Equal(t, "mai_current", captured.SubmitFieldsRequest.InteractionID.Value)
}

func TestSubmit_ExplicitInteractionIDIsNotOverwritten(t *testing.T) {
capturePtermOutput(t)
var captured kernel.AuthConnectionSubmitParams
fake := canonicalSubmitFake("mai_current", &captured)
getCalls := 0
inner := fake.GetFunc
fake.GetFunc = func(ctx context.Context, id string, opts ...option.RequestOption) (*kernel.ManagedAuth, error) {
getCalls++
return inner(ctx, id, opts...)
}
c := AuthConnectionCmd{svc: fake}
require.NoError(t, c.Submit(context.Background(), AuthConnectionSubmitInput{
ID: "auth_1",
SelectedChoiceID: "choice_sms",
// Pinning an older interaction is how a caller detects that the flow moved
// on, so the CLI must forward it untouched.
InteractionID: "mai_pinned",
}))
assert.Equal(t, 0, getCalls)
require.True(t, captured.SubmitFieldsRequest.InteractionID.Valid())
assert.Equal(t, "mai_pinned", captured.SubmitFieldsRequest.InteractionID.Value)
}

func TestSubmit_LegacyModeOmitsInteractionID(t *testing.T) {
capturePtermOutput(t)
var captured kernel.AuthConnectionSubmitParams
fake := &FakeAuthConnectionService{
Expand All @@ -851,11 +981,61 @@ func TestSubmit_CanonicalFieldValues(t *testing.T) {
}
c := AuthConnectionCmd{svc: fake}
require.NoError(t, c.Submit(context.Background(), AuthConnectionSubmitInput{
ID: "auth_1",
FieldValues: map[string]string{"username": "me"},
}))
// The API rejects an interaction ID paired with a legacy submit mode.
assert.False(t, captured.SubmitFieldsRequest.InteractionID.Valid())
}

func TestSubmit_InteractionIDRequiresCanonicalMode(t *testing.T) {
capturePtermOutput(t)
c := AuthConnectionCmd{svc: &FakeAuthConnectionService{}}
err := c.Submit(context.Background(), AuthConnectionSubmitInput{
ID: "auth_1",
FieldValues: map[string]string{"username": "me"},
InteractionID: "mai_current",
})
require.Error(t, err)
assert.Contains(t, err.Error(), "the --interaction-id flag is only valid with --field-value or --choice-id")
}

func TestSubmit_CanonicalWithoutPendingInteractionErrors(t *testing.T) {
capturePtermOutput(t)
submitted := false
fake := &FakeAuthConnectionService{
GetFunc: func(ctx context.Context, id string, opts ...option.RequestOption) (*kernel.ManagedAuth, error) {
return &kernel.ManagedAuth{ID: id}, nil
},
SubmitFunc: func(ctx context.Context, id string, body kernel.AuthConnectionSubmitParams, opts ...option.RequestOption) (*kernel.SubmitFieldsResponse, error) {
submitted = true
return &kernel.SubmitFieldsResponse{Accepted: true}, nil
},
}
c := AuthConnectionCmd{svc: fake}
err := c.Submit(context.Background(), AuthConnectionSubmitInput{
ID: "auth_1",
SelectedChoiceID: "choice_sms",
})
require.Error(t, err)
assert.Contains(t, err.Error(), "no canonical interaction awaiting input")
assert.False(t, submitted)
}

func TestSubmit_CanonicalGetErrorSurfaced(t *testing.T) {
capturePtermOutput(t)
fake := &FakeAuthConnectionService{
GetFunc: func(ctx context.Context, id string, opts ...option.RequestOption) (*kernel.ManagedAuth, error) {
return nil, errors.New("boom")
},
}
c := AuthConnectionCmd{svc: fake}
err := c.Submit(context.Background(), AuthConnectionSubmitInput{
ID: "auth_1",
CanonicalFieldValues: map[string]string{"field_email": "me@example.com"},
}))
assert.Equal(t, map[string]string{"field_email": "me@example.com"}, captured.SubmitFieldsRequest.FieldValues)
assert.Nil(t, captured.SubmitFieldsRequest.Fields)
})
require.Error(t, err)
assert.Contains(t, err.Error(), "interaction ID resolution")
}

func TestSubmit_CanonicalAndLegacyAreMutuallyExclusive(t *testing.T) {
Expand Down
Loading
Loading