Files
木杉 0493db0cd1 feat(apps): add +export to download an app's source code as a zip (#2594)
* feat(apps): add +export to download an app's source code as a zip

Adds `lark-cli apps +export` to export a Miaoda app's source as a zip
archive via POST /open-apis/spark/v1/apps/export. Accepts exactly one
locator: --app-id or --meta-token (a creative app's share-link token),
plus optional --checkpoint-id and --output.

The client rejects non-archive responses instead of saving them: an
error envelope (JSON, or any non-archive content-type) is surfaced as an
error rather than written to the output file, using a content-type
allowlist. Includes the +export shortcut, its tests, and lark-apps skill
docs.

* fix(apps): correct +export not-published guidance to match gateway

The gateway reports an unpublished artifact-hosted app as HTTP 200 + JSON
{"code":40901,"msg":"app not published"}, which flows through the envelope
classifier rather than classifyExportErr's HTTP-422 branch. That code is not in
the shared spark table, so the caller got the raw message with no next step.

- annotate the live 40901 path with a publish-first hint and the
  failed_precondition subtype so its taxonomy matches the 422 sibling
- correct the defensive HTTP-422 branch: replace the stale 'code not in git /
  file storage' guidance with the publish-first semantics; share the hint text
  via a const so the two paths cannot drift
- update tests and the skill reference to the real not-published behavior; add a
  negative case pinning that non-40901 envelope codes get no publish hint
- drop an orphaned exportLookup comment left by the earlier path->body change

* fix(apps): drop +export --checkpoint-id until its value source exists

The flag took a checkpoint id but nothing in lark-cli surfaces a valid one:
there is no command to list an app's checkpoints, and the id is a server-side
DB row key. A caller (human or agent) has no way to know what to pass, so an
arbitrary value just yields a server invalid-argument. Removing the flag until
the feature is designed avoids exposing an uncallable knob.

- remove the --checkpoint-id flag, its validator, and the checkpoint_id body
  field; drop the now-unused strconv import
- remove the two checkpoint-specific tests and the flag's use in the dry-run test
- update the skill reference: drop the flag, its example, and the error-table
  mention; reword the commit-vs-sandbox note to not lean on the flag concept

Export still works by app_id or meta_token and always returns the latest commit
(git-form) or latest published build (artifact-hosted).
2026-09-11 14:50:38 +08:00
..