Commit Graph

54 Commits

Author SHA1 Message Date
github-actions[bot] 5f0e2061e8 Version Packages (#69)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.4.3
2026-05-05 07:38:18 -04:00
Dan Hill 8cc93e9906 feat: allow writing payment credentials to file to avoid context (#67) 2026-05-04 17:50:34 -04:00
Dan Hill 046557ebda Docs, skill improvements 2026-05-03 (#68)
* WIP

* fix totals schema type

* Improve copy with dante

* fix: formatting

* fix: minor path fix

* fix: correctly handle update notifier in TTY and non-TTY modes

* fix: update package to correct

* fix: formatting

* fix: improve update notifier
2026-05-04 17:49:03 -04:00
Gus 59a0fe1956 fix(sdk): restrict the auth config file to the owning user (mode 0o600) (#51)
The Storage class in `packages/sdk/src/utils/storage.ts` constructed a
`Conf` instance without passing `configFileMode`, so the on-disk file
inherited conf's default (0o666 masked by umask, typically 0o644 on
macOS and Linux).

The file holds the OAuth `access_token` and `refresh_token` from
`auth login`, plus — during a pending device-auth window — the
`device_code` and verification phrase written by the agent-mode
`auth login` flow at packages/cli/src/commands/auth/index.tsx:50.

With 0o644 perms, any other local user (shared dev workstations,
multi-user CI runners, lab machines) can:

- Read the access + refresh tokens and call the Link API as the
  victim — including `GET /spend_requests/{id}?include=card` to
  retrieve unmasked card details from approved spend requests.
- During an active login window, read the `device_code` and race the
  legitimate `auth status --interval` poll loop to
  `/device/token`. OAuth 2.0 device-flow polls return tokens to the
  first caller after user approval; the device_code is the polling
  client's secret, and it should never reach disk in a world-readable
  form.

This change passes `configFileMode: 0o600` to the Conf constructor.
Owner-only matches the convention used by gh, aws, mercury-cli, and
similar credential-bearing CLIs. conf writes via atomic rename, so
existing 0o644 files are remediated automatically on the next config
write (next setAuth, clearAuth, or setPendingDeviceAuth).

For testability, the `Storage` class is now exported and accepts an
optional `cwd` so unit tests can run against a temp directory instead
of the real platform user-config path.

Tests:
- `writes the config file with mode 0o600 (owner-only)` — fresh write.
- `rewrites with mode 0o600 when an existing file is 0o644` — covers
  the upgrade path from a pre-fix install.
- `also restricts pendingDeviceAuth, which is written to the same
  file` — covers the device_code race-window vector.

Skipped on Windows (NTFS uses ACLs; POSIX mode bits don't reflect
actual access).
2026-05-04 17:48:52 -04:00
github-actions[bot] 5c49714bce Version Packages (#66)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.4.2
2026-05-02 13:07:29 -04:00
Dan Hill 90fc1838a1 Improve plugins (#64)
* feat: add claude marketplace.json and improve plugins

* changeset

* fix: formatting
2026-05-02 13:02:17 -04:00
Dan Hill 4ee0eb19e1 fix: better document how line items and totals can be passed (#65) 2026-05-02 13:01:15 -04:00
Ryan Aubrey 317eba8a1f Add viem as an explicit dependency (#61) 2026-05-02 12:54:04 -04:00
github-actions[bot] afd09b4e70 Version Packages (#53)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.4.1
2026-04-29 20:45:31 -04:00
Pejman Pour-Moezzi 21bc584091 fix: fail spend request polling timeout (#56) 2026-04-29 19:53:25 -04:00
Dan Hill 5e03819589 fix: bump npm (#52) 2026-04-29 14:16:42 -04:00
github-actions[bot] 28fac7f129 Version Packages (#50)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.4.0
2026-04-29 14:13:44 -04:00
Dan Hill a618ce232d Fix oncomplete (#49)
* fix: correctly expose the SPT in the Ink output

* fix: correctly expose the SPT in the Ink output

* fix: stop spend-request commands from making duplicate API calls

The interactive (Ink) path for create, update, request-approval, and
retrieve each rendered a component that called the API, then made a
second identical API call in waitUntilExit().then() to obtain a value
to resolve the Promise. Thread the result back through onComplete so
index.tsx can resolve with the component's result directly.

Committed-By-Agent: claude

* fix: use ref to track latest request in retrieve polling effect

Using `request` state directly in the polling useEffect timeout path
triggered a biome exhaustive-deps lint error. Track the latest value
in a ref so the polling effect dependency array stays stable.

Committed-By-Agent: claude

* changeset

* fix: remove unused file
2026-04-29 14:03:00 -04:00
Dan Hill 60551347c3 Ink cleanup (#48) 2026-04-29 13:46:20 -04:00
github-actions[bot] a4657c9e3f Version Packages (#47)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.3.1
2026-04-29 11:57:53 -04:00
Steve Kaliski b061e10d27 checklist for onboard/demo flow (#45)
* add checklist style flow for onboard/demo

* add changeset

* fix fmt

* update galtee link

* continue to show credential in demo flow after it ends

* misc polish

* update text

* fmt
2026-04-29 11:54:24 -04:00
jliwag-stripe 334ff3986d Update issue-triggered-create-jira.yml (#43)
Change the target project from PQTEST to PQ.
2026-04-28 17:31:51 -07:00
Ryan Aubrey ec7117bf9f Add back human output for auth status (#44) 2026-04-28 20:29:08 -04:00
github-actions[bot] 0007424700 Version Packages (#41)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.3.0
2026-04-28 19:19:47 -04:00
Dan Hill cd84685f22 Onboarding Experience (#15)
Add a new user onboarding command
2026-04-28 19:17:44 -04:00
Dan Hill 8f40c41515 fix tests (#42) 2026-04-28 19:14:55 -04:00
Dan Hill facab3c453 Fix typo in readme and add MCP/CLI mapping to skill
* fix: typo in readme; add cli->mcp mapping to skill file

* changeset
2026-04-28 16:14:15 -04:00
github-actions[bot] 4959851797 Version Packages (#40)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.2.3
2026-04-28 15:37:52 -04:00
Steve Kaliski de325f19b0 polling commands only emit when response has changed (#39) 2026-04-28 14:16:49 -04:00
github-actions[bot] 14ee57dc0d Version Packages (#36)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.2.2
2026-04-28 00:14:04 -04:00
Steve Kaliski f6803a5f5c add mcp instructions in readme (#30) 2026-04-27 23:58:38 -04:00
Steve Kaliski f8f51a610e update plugins (#29)
* add local Codex marketplace for Link plugin

* update claude plugin

* add changeset
2026-04-27 23:58:30 -04:00
bendavis-stripe 105978a3e3 Fix Card.valid_until type to match API response (#28)
* Fix Card.valid_until type to match API response

The API returns valid_until as an ISO 8601 string, but the Card type
declared it as number. The interactive retrieve component multiplied
the string by 1000 to create a Date, producing NaN and crashing with
"Invalid time value" on toISOString().

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Committed-By-Agent: claude

* Fix biome formatting

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Committed-By-Agent: claude

---------

Co-authored-by: Ben Davis <ben@bencdavis.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-27 16:05:14 -07:00
Steve Kaliski 6b1079be96 update claude file for spend-intent -> spend-request (#26) 2026-04-27 19:00:15 -04:00
github-actions[bot] 178c89e268 Version Packages (#27)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.2.1
2026-04-27 17:54:35 -04:00
Steve Kaliski ef4e3620d4 fix notifier (#25)
* add notifier

* add changeset

* fix
2026-04-27 17:50:19 -04:00
shirleyz-stripe 471cbb7cc5 Replace passphrase with phrase across repo (#24) 2026-04-27 16:54:56 -04:00
jliwag-stripe c1599846df Update issue-triggered-create-jira.yml (#23)
Add bug as default issuetype and include "project-LINK_AI_WALLET" label.
2026-04-27 10:44:11 -07:00
github-actions[bot] ea13c03421 Version Packages (#22)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.2.0
2026-04-27 13:40:01 -04:00
Steve Kaliski eb2115d658 migrate commander -> incur enabling mcp server (#18)
* migrate commander -> incur enabling mcp server

* save

* use incur skill handling and clarify to use mcp if running

* add changeset

* fix type error

* fix fmt

* fix tests

* fmt
2026-04-27 13:37:10 -04:00
Steve Kaliski ae735ec096 add changeset for update-notifier and bug fixes (#21)
* add changeset

* add mpp parsing
2026-04-27 13:19:21 -04:00
Brendan Ryan b976540828 refactor: simplify MPP pay credential creation (#19)
* refactor: simplify MPP pay credential creation

* fix: apply biome formatter
2026-04-27 12:25:33 -04:00
Brendan Ryan ef5c1acf19 fix: align MPP pay retry failures across modes (#20) 2026-04-27 01:45:09 -04:00
Dan Hill 91ce9f035d Update notifier
Use update notifier to indicate new versions. In TTY outputs, this is a very standard update-notifier integration. For JSON outputs consumed by agents, we include the info in the auth status command to not interfere with agents parsing output in other commands.
2026-04-25 17:30:46 -04:00
Dan Hill 15bb366d4d fix: better guide skill to only create request when total amount is known (#16) 2026-04-25 17:29:46 -04:00
dependabot[bot] 95a3d26f15 Bump postcss from 8.5.8 to 8.5.10 (#13)
Bumps [postcss](https://github.com/postcss/postcss) from 8.5.8 to 8.5.10.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](https://github.com/postcss/postcss/compare/8.5.8...8.5.10)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.10
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-25 15:27:09 -04:00
jliwag-stripe a24135793e Create issue-triggered-create-jira.yml (#12)
* Create issue-triggered-create-jira.yml

* Potential fix for pull request finding 'CodeQL / Workflow does not contain permissions'

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>

---------

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2026-04-24 14:25:37 -07:00
kreese-stripe 11bdb9ae01 feat: call /device/revoke endpoint on auth logout call (#11)
* feat: call /device/revoke endpoint on auth logout call

* fmt
2026-04-24 16:27:54 -04:00
github-actions[bot] bb26c4e20a Version Packages (#10)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.1.2
2026-04-24 10:41:45 -04:00
Steve Kaliski ee734e72da add changeset patch for skill (#9) 2026-04-24 10:39:42 -04:00
Dan Hill 45cf25be6f Skill improvements (#8)
npx skills add for skill installation
npm install -g for installing from skill file
remove the unneeded --install option
remove some duplicative instructions
tell it to use --include card when retrieving a card
tell it to check auth status before running a new login command
2026-04-24 10:33:22 -04:00
Steve Kaliski c9a2c2cf91 update release file to support trusted publishing (#7) 2026-04-23 22:33:58 -04:00
github-actions[bot] d70d8565a5 Version Packages (#6)
* Version Packages

* update biome

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Steve Kaliski <stevekaliski@stripe.com>
2026-04-23 22:09:22 -04:00
Steve Kaliski 546d6acf79 add changeset (#5) 2026-04-23 21:54:07 -04:00
Steve Kaliski c1e9a2f4b0 dont include npm build files in git (#4) 2026-04-23 21:45:05 -04:00