mirror of
https://gitea.com/gitea/tea.git
synced 2026-09-15 11:28:11 +02:00
Implements #1087. Adds `tea login status [<login name>] [-o <format>]`, which verifies the stored token for one or all configured logins and reports: - login name/URL and default status - whether the token is valid (via `GET /api/v1/user`) - auth method and token expiry - whether the git credential helper is configured Machine-readable output is available via the usual `-o` formats with fields `name`, `url`, `user`, `valid`, `auth_method`, `token_expiry`, `helper`, and `default`. Reviewed-on: https://gitea.com/gitea/tea/pulls/1105 Reviewed-by: bircni <bircni@icloud.com>
This commit is contained in:
@@ -48,6 +48,29 @@ func SetupHelper(login config.Login) (ok bool, err error) {
|
||||
return true, nil
|
||||
}
|
||||
|
||||
// HasGitCredentialHelper reports whether tea is registered as a git credential
|
||||
// helper for the given login. It mirrors the global git config lookup used by
|
||||
// SetupHelper.
|
||||
func HasGitCredentialHelper(login config.Login) bool {
|
||||
if login.URL == "" {
|
||||
return false
|
||||
}
|
||||
|
||||
helperKey := fmt.Sprintf("credential.%s.helper", login.URL)
|
||||
currentHelpers, err := exec.Command("git", "config", "--global", "--get-all", helperKey).Output()
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
|
||||
for _, line := range strings.Split(strings.ReplaceAll(string(currentHelpers), "\r", ""), "\n") {
|
||||
if strings.HasSuffix(strings.TrimSpace(line), "login helper") {
|
||||
return true
|
||||
}
|
||||
}
|
||||
|
||||
return false
|
||||
}
|
||||
|
||||
// CreateLogin create a login to be stored in config
|
||||
func CreateLogin(ctx stdctx.Context, name, token, user, passwd, otp, scopes, sshKey, giteaURL, sshCertPrincipal, sshKeyFingerprint string, insecure, sshAgent, versionCheck, addHelper bool) error {
|
||||
// checks ...
|
||||
|
||||
@@ -0,0 +1,67 @@
|
||||
// Copyright 2026 The Gitea Authors. All rights reserved.
|
||||
// SPDX-License-Identifier: MIT
|
||||
|
||||
package task
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"gitea.dev/tea/modules/config"
|
||||
"gitea.dev/tea/modules/print"
|
||||
)
|
||||
|
||||
// CheckLoginStatus verifies the stored token for a login against the server and
|
||||
// returns a printable status. Unlike config.Login.Client, refresh failures are
|
||||
// captured in the returned status instead of terminating the process.
|
||||
func CheckLoginStatus(ctx context.Context, login *config.Login) print.LoginStatus {
|
||||
status := print.LoginStatus{
|
||||
Name: login.Name,
|
||||
URL: login.URL,
|
||||
AuthMethod: loginAuthMethod(login),
|
||||
TokenExpiry: loginTokenExpiry(login),
|
||||
Helper: HasGitCredentialHelper(*login),
|
||||
Default: login.Default,
|
||||
}
|
||||
|
||||
if login.GetAccessToken() == "" {
|
||||
status.Error = "Login failed: no access token configured"
|
||||
return status
|
||||
}
|
||||
|
||||
if err := login.RefreshOAuthTokenIfNeeded(); err != nil {
|
||||
status.Error = "Token refresh failed: " + strings.TrimPrefix(err.Error(), "failed to refresh token: ")
|
||||
return status
|
||||
}
|
||||
|
||||
// A successful refresh updates the token in the secure store, so re-read the
|
||||
// expiry for the status line.
|
||||
status.TokenExpiry = loginTokenExpiry(login)
|
||||
|
||||
user, _, err := login.ClientWithoutRefresh().Users.GetMyUserInfo(ctx)
|
||||
if err != nil {
|
||||
status.Error = fmt.Sprintf("Login failed: %s", err)
|
||||
return status
|
||||
}
|
||||
|
||||
status.Valid = true
|
||||
status.User = user.UserName
|
||||
return status
|
||||
}
|
||||
|
||||
func loginAuthMethod(login *config.Login) string {
|
||||
if login.IsOAuth() {
|
||||
return config.AuthMethodOAuth
|
||||
}
|
||||
return "token"
|
||||
}
|
||||
|
||||
func loginTokenExpiry(login *config.Login) time.Time {
|
||||
expiry := login.GetTokenExpiry()
|
||||
if expiry.Equal(time.Unix(0, 0)) {
|
||||
return time.Time{}
|
||||
}
|
||||
return expiry
|
||||
}
|
||||
@@ -0,0 +1,75 @@
|
||||
// Copyright 2026 The Gitea Authors. All rights reserved.
|
||||
// SPDX-License-Identifier: MIT
|
||||
|
||||
package task
|
||||
|
||||
import (
|
||||
"context"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"path/filepath"
|
||||
"testing"
|
||||
|
||||
"gitea.dev/tea/modules/config"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
)
|
||||
|
||||
func TestCheckLoginStatus(t *testing.T) {
|
||||
// Keep helper detection isolated from the developer's real git config.
|
||||
t.Setenv("GIT_CONFIG_GLOBAL", filepath.Join(t.TempDir(), ".gitconfig"))
|
||||
|
||||
t.Run("valid token", func(t *testing.T) {
|
||||
server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
assert.Equal(t, "/api/v1/user", r.URL.Path)
|
||||
assert.Equal(t, "token secret-token", r.Header.Get("Authorization"))
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
_, _ = w.Write([]byte(`{"id":1,"login":"alice"}`))
|
||||
}))
|
||||
defer server.Close()
|
||||
|
||||
status := CheckLoginStatus(context.Background(), &config.Login{
|
||||
Name: "test",
|
||||
URL: server.URL,
|
||||
Token: "secret-token",
|
||||
VersionCheck: false,
|
||||
})
|
||||
|
||||
assert.True(t, status.Valid)
|
||||
assert.Empty(t, status.Error)
|
||||
assert.Equal(t, "test", status.Name)
|
||||
assert.Equal(t, server.URL, status.URL)
|
||||
assert.Equal(t, "alice", status.User)
|
||||
assert.Equal(t, "token", status.AuthMethod)
|
||||
assert.False(t, status.Helper)
|
||||
})
|
||||
|
||||
t.Run("invalid token", func(t *testing.T) {
|
||||
server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
w.WriteHeader(http.StatusUnauthorized)
|
||||
_, _ = w.Write([]byte(`{"message":"token is invalid"}`))
|
||||
}))
|
||||
defer server.Close()
|
||||
|
||||
status := CheckLoginStatus(context.Background(), &config.Login{
|
||||
Name: "test",
|
||||
URL: server.URL,
|
||||
Token: "expired-token",
|
||||
VersionCheck: false,
|
||||
})
|
||||
|
||||
assert.False(t, status.Valid)
|
||||
assert.Contains(t, status.Error, "token is invalid")
|
||||
})
|
||||
|
||||
t.Run("missing token", func(t *testing.T) {
|
||||
status := CheckLoginStatus(context.Background(), &config.Login{
|
||||
Name: "test",
|
||||
URL: "https://gitea.example.com",
|
||||
})
|
||||
|
||||
assert.False(t, status.Valid)
|
||||
assert.Contains(t, status.Error, "no access token configured")
|
||||
})
|
||||
}
|
||||
Reference in New Issue
Block a user