Filing-gate class: ① a defect with a named landing site and a measured reach (class a, a public door).
- Landing site:
packages/cli/src/utils/api-client.ts:56-85. createApiClient reads only ~/.objectstack/credentials.json, the os login session. Its default server URL is http://localhost:3000.
reach: os environments list|show|create|bind|switch. They are the second step of the documented cloud flow, in packages/cli/README.md (Cloud) and content/docs/deployment/cli.mdx.
Measured by #21310's os-dev (round report 5947221232), with HOME holding only ~/.objectstack/cloud.json, the state after os cloud login, pointed at a local echo server:
- All five
os environments subcommands exit 1 with "Authentication required. Please run os login or set OS_TOKEN environment variable." before sending any request.
os login --help says "For the hosted package registry, use os cloud login instead". So a hosted user is sent from one command to the other and back.
os package publish, by contrast, reads cloud.json: with cloud.json alone its request carries that session's bearer.
environments/create.ts:15-30 writes the active environment into cloud.json when the control plane matches, so these commands are built to run against the cloud control plane.
Where things stand: PR #21354 (card #21310) makes the README state this behaviour truthfully, in a per-command "Credentials and server URL" table. It changes no code, so the gap remains.
Shapes (a product decision, not a ruling)
os environments (through createApiClient or a cloud-specific client) falls back to the cloud.json session and URL, as os package publish already does.
os login against the hosted control plane becomes the documented route for os environments, and os login --help stops redirecting hosted users to os cloud login.
- One stored session for both, which retires the split.
Each shape's reasoning belongs on the four axes. The choice of shape is the maintainer's.
Duplicate check: 464 objectstack issues and PRs listed over REST (open plus the most recently updated closed), titles and bodies grepped for credentials.json near cloud.json, os environments near cloud login / Authentication required, and createApiClient near cloud. No hit.
Filed by the maintainer direct-dispatch session (session_018gA1pE6eJtwHhqx72G8U9X, Seat: domain:devx#3). ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim.
Dedupe words: os environments cloud login session · Authentication required os login · credentials.json cloud.json · createApiClient cloud session
Generated by Claude Code
Filing-gate class: ① a defect with a named landing site and a measured reach (class a, a public door).
packages/cli/src/utils/api-client.ts:56-85.createApiClientreads only~/.objectstack/credentials.json, theos loginsession. Its default server URL ishttp://localhost:3000.reach:os environments list|show|create|bind|switch. They are the second step of the documented cloud flow, inpackages/cli/README.md(Cloud) andcontent/docs/deployment/cli.mdx.Measured by #21310's os-dev (round report 5947221232), with
HOMEholding only~/.objectstack/cloud.json, the state afteros cloud login, pointed at a local echo server:os environmentssubcommands exit 1 with "Authentication required. Please runos loginor set OS_TOKEN environment variable." before sending any request.os login --helpsays "For the hosted package registry, useos cloud logininstead". So a hosted user is sent from one command to the other and back.os package publish, by contrast, readscloud.json: withcloud.jsonalone its request carries that session's bearer.environments/create.ts:15-30writes the active environment intocloud.jsonwhen the control plane matches, so these commands are built to run against the cloud control plane.Where things stand: PR #21354 (card #21310) makes the README state this behaviour truthfully, in a per-command "Credentials and server URL" table. It changes no code, so the gap remains.
Shapes (a product decision, not a ruling)
os environments(throughcreateApiClientor a cloud-specific client) falls back to thecloud.jsonsession and URL, asos package publishalready does.os loginagainst the hosted control plane becomes the documented route foros environments, andos login --helpstops redirecting hosted users toos cloud login.Each shape's reasoning belongs on the four axes. The choice of shape is the maintainer's.
Duplicate check: 464 objectstack issues and PRs listed over REST (open plus the most recently updated closed), titles and bodies grepped for
credentials.jsonnearcloud.json,os environmentsnearcloud login/Authentication required, andcreateApiClientnearcloud. No hit.Filed by the maintainer direct-dispatch session (
session_018gA1pE6eJtwHhqx72G8U9X,Seat: domain:devx#3). ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim.Dedupe words:
os environments cloud login session·Authentication required os login·credentials.json cloud.json·createApiClient cloud sessionGenerated by Claude Code