Files
dc-bytedance fdc1ba4df7 feat: use remote scopes.json for login scope recommendations (#1799)
* feat: use remote scopes.json for login scope recommendations

Switch auth login's recommended-permission source from the compiled-in
local table to a scopes.json fetched from the platform at login time.

- add internal/auth/remote_scopes.go: brand-addressed GET with a ~1s
  timeout and whole-file (binary) validation; scopes are used verbatim
  when the file is valid, and any fetch/parse/format failure falls back
  silently to the existing local computation
- login.go: fetch remote scopes once per login and use them for domain
  validation, all-expansion, and per-domain scope selection; drop the
  terminal interactive page and the local auto-approve filter chain, so
  --recommend is now equivalent to --domain all
- remove login_interactive.go and the service-description getters left
  orphaned by the interactive-page removal
- keep the three entry flags (bare login / --recommend / --domain all)
  as an equivalent transitional surface

* refactor: remove orphaned auto-approve loader and harden scope check

* fix: accept variable segment counts in remote scope validation

* feat(auth): add support for status message from device flow auth

* fix(auth): remove message field from login warning payload

* fix(auth/login): improve login result heading and warning hint logic

* fix: resolve auth scopes locally for custom builds and exclusions

Remote-first login (reading the published scopes.json) can drop scopes
that a specific build or the local resolution still legitimately covers.
Two cases are now handled locally:

- A build that injected business commands via WithCommandSets has a
  scope universe the standard-CLI scopes.json does not cover. Detect it
  by comparing registered command paths against the built-in set and
  skip the remote fetch, so such a build resolves locally instead of
  silently losing its custom scopes.
- Fold the local domain resolution into the --exclude validation
  universe. Once the server drops a batch-withheld scope
  (im:message.send_as_user) from the published list, the remote
  candidate set no longer carries it, but --domain im --exclude
  im:message.send_as_user must stay a valid no-op; a domain that never
  had the scope still rejects it as unknown.

Also raise the remote fetch timeout from 1s to 2s, and make the auth
tests hermetic by defaulting the remote fetch to unavailable in
TestMain (a test that needs a specific remote overrides the seam).

---------
2026-09-07 20:19:53 +08:00
..
2026-06-17 16:29:33 +08:00