Commit Graph

129 Commits

Author SHA1 Message Date
jlau-stripe 7dadfcd1ef patch version (#187) @stripe/link-cli@0.8.3 2026-07-07 10:34:46 -04:00
jlau-stripe b3b25946c9 feat: surface verification_url in spend-request error output (#186)
* feat: surface verification_url in spend-request error output

When the API returns additional_verification_required, surface the
verification_url so users know where to complete stepup verification.
Also fixes interactive mode hanging on error by calling useApp().exit().

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Committed-By-Agent: claude

* fix: resolve biome lint and format errors in spend-request commands

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Committed-By-Agent: claude

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-07 10:20:27 -04:00
dmillerjunk-stripe 85084247f8 feat: Add Origin Filter to Transactions Endpoint, fix date filters (#185) 2026-06-30 11:27:54 -04:00
dmillerjunk-stripe c62c4fe22b feat: add transactions command (#175)
Committed-By-Agent: codex

Committed-By-Agent: codex

Co-authored-by: codex <noreply@openai.com>
2026-06-26 15:03:32 -04:00
github-actions[bot] 1ac34e94a9 Version Packages (#179)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.8.2
2026-06-26 14:17:06 -04:00
sylwang-stripe 1a0bf3099d update readme (#178) 2026-06-26 12:02:56 -04:00
sylwang-stripe 6f34471086 make payment method id optional for spend-request create (#172)
* make payment method id optional in schema for spend request create

* update payment details type to optional
2026-06-24 15:16:04 -04:00
github-actions[bot] acf04687f0 Version Packages (#173)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.8.1
2026-06-24 08:42:45 -07:00
drapeau-stripe dd0e30329b chore: add changeset for report command docs (#170)
#150 added the report-outcomes docs to the README (which ships in the npm
package) and the create-payment-credential skill, but merged without a
changeset. Add a patch changeset so the next release publishes the updated
README.


Committed-By-Agent: claude

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-24 08:34:41 -07:00
drapeau-stripe f56968cd2c [Link Agent Wallet] Add reporting instructions to SKILL.md and README (#150)
* docs: add report command instructions to SKILL.md and README

- SKILL.md: reporting instructions (when to report, tag reference, examples)
- README.md: report outcomes section with usage examples

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Committed-By-Agent: claude

* docs: make outcome reporting opt-in and add tag guidance

Address review feedback on the reporting docs:
- Soften the "REQUIRED" / "always report" language to encouraged-but-optional
  in both SKILL.md and README, so reporting is suggested rather than mandated
  for now.
- Add guidance to prefer the most specific tag and use `other` only when none
  apply (describing details in --freeform-context).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Committed-By-Agent: claude

* docs: reword report rationale to "improve checkout for agents"

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Committed-By-Agent: claude

* docs: align SKILL.md report rationale wording with README

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Committed-By-Agent: claude

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-06-23 15:29:37 -07:00
github-actions[bot] d65a4ce616 Version Packages (#168)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.8.0
2026-06-23 15:11:26 -04:00
sylwang7 5827e02f6c v0.8.0 changeset (#167) 2026-06-23 13:11:21 -04:00
sylwang7 9386082c24 Add --include-history flag to surface all spend request history in spend request list (#165)
* add --include-history flag to spend request list

* conditionally display empty state message

* conditionally display text
2026-06-22 18:28:49 -04:00
sylwang7 bab4bb2b14 surface user eligibility in auth login and payment-methods list (#162)
* surface user eligibility in link cli

* fix biome formatting
2026-06-22 17:28:13 -04:00
nvp-stripe 1bbc891209 Revert "Add Link Pay Token flow to create-payment-credential skill (#163)" (#166)
This reverts commit f13696a29b.
2026-06-22 17:06:58 -04:00
nvp-stripe f13696a29b Add Link Pay Token flow to create-payment-credential skill (#163)
* update SKILL.md

* update skill.md
2026-06-22 16:47:40 -04:00
drapeau-stripe d34ebd0053 [Link Agent Wallet] Add report command for agent observability (#149)
* feat: add report command for agent observability

Add `link-cli report` command for reporting purchase outcomes (success,
blocked, abandoned) after every agent purchase attempt.

- packages/cli/src/commands/report/schema.ts — Zod schema using SDK constants
- packages/cli/src/commands/report/index.tsx — Command definition
- packages/cli/src/utils/resource-factory.ts — Add createReportResource()
- packages/cli/src/cli.tsx — Register the command

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Committed-By-Agent: claude

* fix: register report as a leaf command so CLI flags parse

The report command was registered with cli.command('', {...}) under a
router Cli. The empty-string subcommand name broke flag parsing
(`link-cli report --domain ...` treated --domain as a subcommand) and
produced the MCP tool name `report_`. Switch to the leaf-command form
used by demo/onboard — pass options/run directly to Cli.create — and
gate auth with requireAuthGuard inside run, matching spend-request.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Committed-By-Agent: claude

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-06-18 09:11:12 -07:00
sylwang7 fc9547dff2 Skip re-auth if a usable session already exists (#161)
* skip re-auth if a usable session already exists

* fix formatting

* update tests

* format tests

* clean up
2026-06-17 14:03:09 -04:00
github-actions[bot] f70d1fc375 Version Packages (#160)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.7.4
2026-06-15 12:37:31 -04:00
jlau-stripe c2fc0659ee v0.7.4 changeset (#159) 2026-06-15 12:00:14 -04:00
nvp-stripe d5044ed5e8 Add link_pay_token field to SpendRequest type (#158)
* add field

* retrieve.tsx updat
2026-06-12 14:12:08 -04:00
kreese-stripe 78f0200ad7 --approve flag for calling delegated endpoint (#154) 2026-06-12 11:47:38 -04:00
github-actions[bot] 67da9a4522 Version Packages (#152)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.7.3
2026-06-10 14:51:20 -04:00
kreese-stripe f83d5cc332 v0.7.3 changeset (#151) 2026-06-10 14:42:14 -04:00
kreese-stripe a87ff0cbe4 feat: update SR max amount (#147)
* update SR max amount

* fmt

* trigger ci

* trigger ci
2026-06-10 12:31:40 -04:00
drapeau-stripe 5521060e19 sdk: add report resource for agent observability (#114)
Add IReportResource interface and ReportResource implementation that
POSTs to /agent_observations. Supports reporting purchase outcomes
(success, blocked, abandoned) with domain, tags, and context.
2026-06-10 09:02:28 -07:00
kreese-stripe e09d499424 Update documented limits (#146) 2026-06-10 10:30:59 -04:00
github-actions[bot] a34aaf9f1c Version Packages (#145)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.7.2
2026-06-08 14:06:09 -04:00
kreese-stripe a30d70bef0 feat: changeset for v0.7.2 (#144)
* pnpm changeset for v0.7.2

* update changeset

* rm old changeset
2026-06-08 14:02:57 -04:00
kreese-stripe 06cc528175 fix: Align on minimum node version requirements across configs (#142)
* Align on minimum node version requirements across configs

* fmt
2026-06-08 13:03:09 -04:00
kreese-stripe 51b0251cd7 feat: Upload SEAs to release artifacts as well (#143)
* Upload SEAs to release artifacts as well

* Updates to SEA Build config

* Fixes to get the SEA builds working

* SEA-specific build config

* revert unneeded changes
2026-06-08 12:50:25 -04:00
github-actions[bot] 328b9d6568 Version Packages (#141)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.7.1
2026-06-05 14:27:27 -04:00
kreese-stripe 13fda7edd1 feat: v0.7.1 changeset (#140) 2026-06-05 14:24:09 -04:00
kreese-stripe b9b41e7aef Upload built cli.js with checksum as release artifact (#139) 2026-06-05 14:02:07 -04:00
kreese-stripe 61303becbe publishable update (#138) @stripe/link-cli@0.7.0 2026-06-05 10:48:53 -04:00
kreese-stripe 079c41da00 pnpm changeset (#137) 2026-06-05 10:39:18 -04:00
jlau-stripe 9d5969df12 Support additional endpoints to auth by env access_token (#134)
* Support additional endpoints to auth by env access_token

* Add tests

* fix formatting
2026-06-03 11:00:47 -04:00
nvp-stripe 31421c6c78 feat(sdk): migrate WebBotAuthResource to POST /web_bot_auth/sign (#122)
* feat(sdk): migrate WebBotAuthResource to POST /web_bot_auth/sign

PR #2208449 (pay-server) added a dedicated signing endpoint. The
credentials endpoint no longer accepts the url parameter or returns
web_bot_auth. Update the SDK resource to call the dedicated endpoint.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Committed-By-Agent: claude

* code review comments

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-02 09:22:51 -04:00
sylwang7 6ea4fbe360 Add payment_status_details to spend request retrieve (#124)
* surface payment_status_details from spend request retrieve API

* fix inline test bold element
2026-06-01 15:05:18 -04:00
kreese-stripe 2049933177 clear any existing auth when calling auth login (#130) 2026-05-29 13:00:39 -04:00
Dan Hill 35023ae48c fix: bump versions to latest (#132) 2026-05-29 12:13:28 -04:00
Dan Hill 560d92238a Cursor plugin (#131)
* feat: add Cursor plugin manifest

Committed-By-Agent: claude

* feat: add Cursor plugin MCP server config

Committed-By-Agent: claude

* feat: add Cursor plugin agent definition

Committed-By-Agent: claude

* feat: add Cursor plugin README

Committed-By-Agent: claude

* fix: cleanup and sync

* fix: biome cleanup
2026-05-29 12:08:09 -04:00
jliwag-stripe 9e1fe045d2 Update issue-triggered-create-jira.yml (#123)
I've added retry mechanism, 4 retries with 15min delay per retry and if retry maxed out it will ping the Slack channel. The code has been tested on my private test repo.
2026-05-28 13:44:45 -07:00
Dan Hill a96c507046 feat: bump to version 0.6.0 (#126) @stripe/link-cli@0.6.0 2026-05-28 16:14:51 -04:00
Dan Hill 18d19579a4 fix: hide web-bot-auth until ready (#125) 2026-05-28 16:07:05 -04:00
Dan Hill fe45662873 HTTP mcp (#121)
* feat: add serve command to expose MCP endpoint over HTTP

Committed-By-Agent: claude

* fix: cleanup and readme

* Potential fix for pull request finding 'CodeQL / Information exposure through a stack trace'

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>

---------

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2026-05-28 15:45:53 -04:00
harryguo-nyc 2639339bfc feat: add spend-request list command (#108)
* feat: add spend-request list command

Implements `spend-request list` subcommand that calls GET /spend_requests,
unwraps the response, and renders active spend requests grouped by status
with color coding. Includes SDK interface update, implementation, Ink UI
component, subcommand registration, and unit/integration tests.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Committed-By-Agent: claude

* fix: correct onComplete type in SpendRequestList to accept null

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Committed-By-Agent: claude

* fix: apply biome formatting to list command files

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Committed-By-Agent: claude

* fix: call exit() after list completes so interactive mode terminates

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Committed-By-Agent: claude

* fix: apply biome formatting to useAsyncAction destructure in list.tsx

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Committed-By-Agent: claude

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-28 10:34:27 -04:00
Dan Hill 0783323004 WIP: auth from env (#107)
* feat: add noRefresh option to createAccessTokenProvider

Committed-By-Agent: claude

* feat: add env-based token provider to ResourceFactory

Committed-By-Agent: claude

* feat: read LINK_ACCESS_TOKEN, LINK_REFRESH_TOKEN, LINK_NO_REFRESH from env

Committed-By-Agent: claude

* docs: add LINK_ACCESS_TOKEN, LINK_REFRESH_TOKEN, LINK_NO_REFRESH to env vars docs

Committed-By-Agent: claude

* fix: auth status shows LINK_ACCESS_TOKEN state instead of stored credentials

Committed-By-Agent: claude

* refactor: extract resolveAuthInfo helper, simplify auth status component

Committed-By-Agent: claude

* fix: formatting
2026-05-27 10:04:43 -04:00
Dan Hill 5d76bf614d feat: document current limits (#104) 2026-05-27 09:00:10 -04:00
Gus d6efd70e01 security: refuse to write credentials through pre-existing symlinks (#94)
* security: refuse to write credentials through pre-existing symlinks

writeCredentialFile (cli/src/utils/credential-output.ts) was vulnerable to
a TOCTOU exfiltration on shared filesystems. The previous flow was:

  fs.access(resolved)         // follows symlinks
  fs.writeFile(resolved, ..., { mode: 0o600 })  // follows symlinks; mode
                                                // applied only if file is
                                                // created, not if exists
  fs.chmod(resolved, 0o600)   // follows symlinks; sets perms on TARGET

If the operator runs `spend-request retrieve <id> --output-file <path>
--force` and an attacker on the same filesystem (CI runner, multi-tenant
host, container with shared /tmp) pre-plants a symlink at <path> pointing
at a file the attacker can already read, the attacker:

  1. Plants <path> as a symbolic link to /tmp/<readable>.
  2. Opens a read fd on /tmp/<readable> while it is world-readable.
  3. Operator runs the command: writeFile follows the symlink and writes
     the full card credential (PAN, CVV, billing address, valid_until) to
     the symlink target.
  4. Operator's chmod 0o600 then locks the target down — too late, the
     attacker's fd was opened before the chmod and survives it.

Verified end-to-end by a Node reproduction: a fresh fd opened against the
target before the operator's writeCredentialFile call reads the JSON-
encoded credential immediately after the call returns, regardless of the
chmod that follows.

Fix replaces fs.access + fs.writeFile + fs.chmod with a single
fs.open(resolved, O_CREAT | O_EXCL | O_WRONLY | O_NOFOLLOW, 0o600). The
mode is set at create time. O_NOFOLLOW makes open fail with ELOOP if the
final path component is a symlink. O_EXCL makes open fail with EEXIST if
the file already exists. Force-mode unlinks any pre-existing entry first
(operating on the symlink itself via fs.unlink, not the target via
fs.writeFile), then takes the same atomic-create path.

Tests added to credential-output.test.ts:
- refuses to write through a symbolic link without force
- refuses to write through a symbolic link with force (target untouched)
- TOCTOU race-fail-closed
- 0o600 mode produced even with --force (regression guard for the
  removed fs.chmod step)

`pnpm test` is green (117/117 across 11 files). Negative control: with
the implementation reverted, two of the new tests fail because the
symlink target is overwritten by the credential JSON.

* security(credential-output): scope POSIX-only protection explicitly

Addresses review feedback on PR #94. Gates O_NOFOLLOW as
constants.O_NOFOLLOW ?? 0 with an inline note on the Windows gap
(O_EXCL still prevents overwriting a pre-existing entry, but the path
no longer provides full no-follow protection there). Trims in-file
comment; the full attack chain stays in the PR body and tests. Drops
the biome-ignore directive that pointed at a non-existent rule.

* security(credential-output): refuse symlinks even with --force

Addresses review feedback on PR #94. The previous revision unlinked any
pre-existing entry in --force mode and then ran the atomic open with
O_EXCL | O_NOFOLLOW. That cleared the path for the create but also
silently destroyed pre-existing symlinks, and the no-follow guarantee
only covered the race window after the unlink.

This refactor inverts the precheck: lstat first, refuse outright when
the final path is a symlink (with or without --force), and only unlink
and recreate for non-symlink existing files. O_EXCL | O_NOFOLLOW remains
the race defense between the precheck and the atomic create.

Tests updated. The without-force symlink case now expects
OUTPUT_FILE_SYMLINK and asserts the symlink survives. The with-force
case is renamed to make the new contract obvious and gets the same
assertions. The dedicated post-unlink-race test is dropped because its
premise (force unlinks the symlink) no longer applies; the regular-file
race defense is exercised by the existing 0o600 test.
2026-05-27 08:54:28 -04:00