Skip to content

openapi-security: print an access token with meshstack auth token - #25

Merged
grubmeshi merged 3 commits into
mainfrom
feature/openapi-security
Oct 5, 2026
Merged

grubmeshi merged 3 commits into
mainfrom
feature/openapi-security

Conversation

@grubmeshi

@grubmeshi grubmeshi commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

openapi-security

The meshStack API docs get an Authentication section that matches what the API really accepts: a bearer token from meshstack login, from an API key, or from a building block run, and Basic only for the deprecated API users of the declarative import. The docs theme offers no interactive OAuth login, so the docs tell a reader to paste the output of meshstack auth token into the Bearer field to try a request against their own meshStack.

This PR:

  • adds meshstack auth token. It prints the access token the resolved credential sends, renewed where it is about to expire, and nothing else on stdout, so $(meshstack auth token) works. Without a credential it points to meshstack login and never opens a browser.
  • writes meshstack login rather than meshstack auth login in help texts, which the Terraform provider shows for profile.
  • stops filtering authentication out of the OpenAPI document (withoutAuthentication in client/openapi). meshstack api-docs now shows the security schemes, the security requirements and /api/login as meshStack publishes them, because the docs now describe authentication correctly.

Tests: acceptance steps only. The browser login and the API key login each take the token meshstack auth token prints, log in with it through meshstack login --apitoken, list workspaces with it, and check that meshstack auth token then prints that API token unchanged and nothing else on stdout.

Cross-repo PRs

  • meshcloud/meshstack-cli (this PR): meshstack auth token, and meshstack login in help texts
  • meshcloud/meshfed-release#11274: spec security schemes, Authentication docs, meshPanel hints

🤖 Generated with Claude Code

Comment thread cmd/auth/token_test.go Outdated
grubmeshi and others added 2 commits October 5, 2026 10:31
It prints the token the resolved credential sends, renewed where it is about
to expire, and nothing else on stdout. Someone who wants to try the API docs
against their meshStack pastes it as the Bearer token there.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Both commands work, and the docs of the CLI, the Terraform provider and
meshStack now name the shorter one throughout.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@grubmeshi
grubmeshi force-pushed the feature/openapi-security branch from 59d5c16 to 4627ee6 Compare October 5, 2026 08:31
@meshcloud-gh-actions

meshcloud-gh-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Coverage of the acceptance run against the meshStack backend, on 64c94ed4af09341b501985fbbeb884c531bfb6ae.

Scope Coverage
Unit tests 79.3%
Acceptance tests 53.0%
Combined 83.5%
Uncovered functions
client/api_key.go:55: meshApiKeyClient.Create 0.0%
client/api_key.go:59: meshApiKeyClient.Read 0.0%
client/api_key.go:63: meshApiKeyClient.Update 0.0%
client/api_key.go:71: meshApiKeyClient.Delete 0.0%
client/api_key_permissions.go:20: ApiKeyPermissions.AllCodes 0.0%
client/api_key_permissions.go:33: ApiKeyPermissions.WorkspaceCodes 0.0%
client/api_key_permissions.go:295: AllApiKeyPermissions 0.0%
client/api_key_permissions.go:299: WorkspacePermissionCodes 0.0%
client/building_block_definition.go:71: MeshBuildingBlockDefinitionApprovalPolicies.NothingRequiresApproval 0.0%
client/building_block_definition.go:82: DisabledSchedule 0.0%
client/building_block_definition.go:89: MeshBuildingBlockDefinitionSchedule.IsDisabled 0.0%
client/building_block_definition.go:93: MeshBuildingBlockDefinitionSpec.HasNeutralPolicies 0.0%
client/building_block_definition.go:97: MeshBuildingBlockDefinitionSpec.WithNeutralPolicies 0.0%
client/building_block_definition.go:166: meshBuildingBlockDefinitionClient.List 0.0%
client/building_block_definition.go:173: meshBuildingBlockDefinitionClient.Read 0.0%
client/building_block_definition.go:177: meshBuildingBlockDefinitionClient.Create 0.0%
client/building_block_definition.go:181: meshBuildingBlockDefinitionClient.Update 0.0%
client/building_block_definition.go:185: meshBuildingBlockDefinitionClient.Delete 0.0%
client/building_block_definition_version.go:100: MeshBuildingBlockType.TagInputTargets 0.0%
client/building_block_definition_version.go:245: meshBuildingBlockDefinitionVersionClient.Create 0.0%
client/building_block_definition_version.go:254: meshBuildingBlockDefinitionVersionClient.Update 0.0%
client/building_block_definition_version_implementation.go:80: MeshBuildingBlockDefinitionImplementation.InferType 0.0%
client/building_block_definition_version_implementation.go:94: MeshBuildingBlockDefinitionImplementation.MarshalJSON 0.0%
client/building_block_definition_version_implementation.go:107: *MeshBuildingBlockDefinitionImplementation.UnmarshalJSON 0.0%
client/building_block_runner.go:82: meshBuildingBlockRunnerClient.Create 0.0%
... and 123 more

covdata func names a method without its receiver, so an entry can belong to an implementation nothing selects rather than to a function the tests never reached. Open the file and line before reading one as a coverage gap.

…meshStack publishes it

The CLI left out the security schemes, the security requirements, the
"Authentication" paragraphs and /api/login, because those paragraphs were
wrong. meshStack's API docs now describe authentication correctly, so the
CLI shows them as published.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@grubmeshi
grubmeshi force-pushed the feature/openapi-security branch from d909147 to 64c94ed Compare October 5, 2026 10:26
@grubmeshi
grubmeshi merged commit 64c94ed into main Oct 5, 2026
11 checks passed
@grubmeshi
grubmeshi deleted the feature/openapi-security branch October 5, 2026 11:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant