Repository navigation
feat(cli): stable device id — login-session record + device header (campus#837) - #30
Merged
Merged
Conversation
…837) This CLI install now presents a stable device identity per the #825 design (device = this install on this machine, client-asserted): - config.get_device_id() mints uid-device-* once and persists it in the config file; reused across logins. - After a successful device-flow login, the echoed user_id drives a best-effort POST /logins/ creating the login-session record with the device id; the session id is stored for logout. An older auth deployment without the route must not fail login. - Logout revokes the stored login-session record via the bearer-owned path (campus#838) alongside the token revocation; best-effort, local id always cleared. - CampusClient sets X-Campus-Device (campus_python.tracing. DEVICE_ID_HEADER) as a default header on the API and auth clients: bearer tokens are shared per (user, client), so the header is the only way server-side spans attribute to this device. Lock bump: campus-api-python -> f40f8af (set_default_header + X-Campus-Device forward). Refs nyjc-computing/campus#837
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CLI half of campus#837 (the CLI device lane from the campus#825 design).
What changes
config.get_device_id()mintsuid-device-*once and persists it in the config file — device = this CLI install on this machine (client-asserted, same trust level as User-Agent, per the accepted design).user_id(campus#838) drives a best-effortPOST /logins/with the device id; the session id is stored for logout. An older auth deployment without the logins route logs a dim note and login still succeeds.DELETE /logins/{id}/via the bearer-owned path (campus#838), alongside the existing RFC 7009 token revocation; best-effort, the local id is always cleared.X-Campus-Deviceon every API/auth call:CampusClientsets it as a default header (campus_python.tracing.DEVICE_ID_HEADER) on both SDK clients — bearer tokens are shared per (user, client), so the header is the only way server-side spans attribute to this device.campus-api-python→ f40f8af (set_default_header+ X-Campus-Device forward).Test plan
tests/unit/test_device_lane.py(9 tests): device id mint/persist/reload, login-session create payload + all failure modes, delete via bearer header + failure modes, device header set on both SDK clients.Ref nyjc-computing/campus#837