mirror of
https://github.com/larksuite/cli.git
synced 2026-09-14 18:42:53 +08:00
fdc1ba4df7
* feat: use remote scopes.json for login scope recommendations Switch auth login's recommended-permission source from the compiled-in local table to a scopes.json fetched from the platform at login time. - add internal/auth/remote_scopes.go: brand-addressed GET with a ~1s timeout and whole-file (binary) validation; scopes are used verbatim when the file is valid, and any fetch/parse/format failure falls back silently to the existing local computation - login.go: fetch remote scopes once per login and use them for domain validation, all-expansion, and per-domain scope selection; drop the terminal interactive page and the local auto-approve filter chain, so --recommend is now equivalent to --domain all - remove login_interactive.go and the service-description getters left orphaned by the interactive-page removal - keep the three entry flags (bare login / --recommend / --domain all) as an equivalent transitional surface * refactor: remove orphaned auto-approve loader and harden scope check * fix: accept variable segment counts in remote scope validation * feat(auth): add support for status message from device flow auth * fix(auth): remove message field from login warning payload * fix(auth/login): improve login result heading and warning hint logic * fix: resolve auth scopes locally for custom builds and exclusions Remote-first login (reading the published scopes.json) can drop scopes that a specific build or the local resolution still legitimately covers. Two cases are now handled locally: - A build that injected business commands via WithCommandSets has a scope universe the standard-CLI scopes.json does not cover. Detect it by comparing registered command paths against the built-in set and skip the remote fetch, so such a build resolves locally instead of silently losing its custom scopes. - Fold the local domain resolution into the --exclude validation universe. Once the server drops a batch-withheld scope (im:message.send_as_user) from the published list, the remote candidate set no longer carries it, but --domain im --exclude im:message.send_as_user must stay a valid no-op; a domain that never had the scope still rejects it as unknown. Also raise the remote fetch timeout from 1s to 2s, and make the auth tests hermetic by defaulting the remote fetch to unavailable in TestMain (a test that needs a specific remote overrides the seam). ---------