Skip to content

cli: os environments * never read the os cloud login session, while os login --help sends hosted users to os cloud login — the documented cloud flow loops #21360

Description

@objectstack-fleet

Filing-gate class: ① a defect with a named landing site and a measured reach (class a, a public door).

  • Landing site: packages/cli/src/utils/api-client.ts:56-85. createApiClient reads only ~/.objectstack/credentials.json, the os login session. Its default server URL is http://localhost:3000.
  • reach: os environments list|show|create|bind|switch. They are the second step of the documented cloud flow, in packages/cli/README.md (Cloud) and content/docs/deployment/cli.mdx.

Measured by #21310's os-dev (round report 5947221232), with HOME holding only ~/.objectstack/cloud.json, the state after os cloud login, pointed at a local echo server:

  • All five os environments subcommands exit 1 with "Authentication required. Please run os login or set OS_TOKEN environment variable." before sending any request.
  • os login --help says "For the hosted package registry, use os cloud login instead". So a hosted user is sent from one command to the other and back.
  • os package publish, by contrast, reads cloud.json: with cloud.json alone its request carries that session's bearer.
  • environments/create.ts:15-30 writes the active environment into cloud.json when the control plane matches, so these commands are built to run against the cloud control plane.

Where things stand: PR #21354 (card #21310) makes the README state this behaviour truthfully, in a per-command "Credentials and server URL" table. It changes no code, so the gap remains.

Shapes (a product decision, not a ruling)

  1. os environments (through createApiClient or a cloud-specific client) falls back to the cloud.json session and URL, as os package publish already does.
  2. os login against the hosted control plane becomes the documented route for os environments, and os login --help stops redirecting hosted users to os cloud login.
  3. One stored session for both, which retires the split.

Each shape's reasoning belongs on the four axes. The choice of shape is the maintainer's.

Duplicate check: 464 objectstack issues and PRs listed over REST (open plus the most recently updated closed), titles and bodies grepped for credentials.json near cloud.json, os environments near cloud login / Authentication required, and createApiClient near cloud. No hit.

Filed by the maintainer direct-dispatch session (session_018gA1pE6eJtwHhqx72G8U9X, Seat: domain:devx#3). ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim.

Dedupe words: os environments cloud login session · Authentication required os login · credentials.json cloud.json · createApiClient cloud session


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratebugSomething isn't workingdomain:clipriority:p2Medium: important, M3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions