mirror of
https://github.com/larksuite/cli.git
synced 2026-07-03 14:02:43 +08:00
Every failure on the authentication, authorization, and configuration
path now surfaces as a typed structured error instead of an ad-hoc
envelope. Users and scripts that consume CLI output get:
- a fixed nine-category taxonomy on the wire, each mapped to a
stable shell exit code (authentication/authorization/config = 3,
network = 4, internal = 5, policy = 6, confirmation = 10)
- identity-aware detail fields (missing_scopes, requested_scopes,
granted_scopes, console_url, log_id, retryable, hint) carried
uniformly on the envelope
- a single canonical policy envelope at exit 6; the legacy
auth_error carve-out is retired
- per-subtype canonical message + hint that preserves Lark's
diagnostic phrasing and routes recovery to the right actor:
app developer (app_scope_not_applied), user (missing_scope,
token_scope_insufficient, user_unauthorized), or tenant admin
(app_unavailable, app_disabled)
- wrong app credentials classify as config/invalid_client whether
surfaced by the Open API endpoint (99991543) or the tenant
access-token mint endpoint (10003 / 10014), instead of
collapsing to a transport error or api/unknown
- local shortcut scope preflight emits the same
authorization/missing_scope envelope (identity + deterministic
missing-scope set) used by the post-call permission path, so AI
consumers read the same structured shape from precheck and from
server-returned permission denial
- streaming download/upload failures keep the same network subtype
split (timeout / TLS / DNS / transport) as the non-stream path
instead of collapsing every cause to a generic transport failure
- console_url is carried only on the bot-perspective
app_scope_not_applied envelope (where the recovery action is
"developer applies the scope at the developer console"); the
user-perspective missing_scope envelope drops the field, since
the only actionable user recovery is `lark-cli auth login --scope`
and pointing an end user at a console they cannot modify is
misleading
- bind workflows (Hermes / OpenClaw / lark-channel) flatten dynamic
Type tags to wire 'config' with the original module name kept
as a metric label
All 10 typed errors are cause-bearing, nil-safe on .Error() and
.Unwrap(), and defensively clone slice setter inputs. Four lint
rules (CheckNilSafeError / CheckBuilderImmutable / CheckUnwrapSymmetry
/ CheckBuildAPIErrorArms) lock these invariants on migrated paths.
122 lines
4.0 KiB
Go
122 lines
4.0 KiB
Go
// Copyright (c) 2026 Lark Technologies Pte. Ltd.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
package auth
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
"fmt"
|
|
"testing"
|
|
|
|
"github.com/larksuite/cli/errs"
|
|
"github.com/larksuite/cli/internal/cmdutil"
|
|
"github.com/larksuite/cli/internal/core"
|
|
)
|
|
|
|
// stubGetAppInfoErr swaps getAppInfoFn for the duration of t so authScopesRun
|
|
// observes a fixed error from the dependency. t.Cleanup restores the prior
|
|
// value so tests cannot leak through the package-level seam.
|
|
func stubGetAppInfoErr(t *testing.T, errToReturn error) {
|
|
t.Helper()
|
|
prev := getAppInfoFn
|
|
getAppInfoFn = func(ctx context.Context, f *cmdutil.Factory, appId string) (*appInfo, error) {
|
|
return nil, errToReturn
|
|
}
|
|
t.Cleanup(func() { getAppInfoFn = prev })
|
|
}
|
|
|
|
// scopesTestFactory builds a Factory + ScopesOptions pair sufficient to drive
|
|
// authScopesRun. Config has a non-empty AppID so we get past the config gate
|
|
// and reach the getAppInfoFn call.
|
|
func scopesTestFactory(t *testing.T) *ScopesOptions {
|
|
t.Helper()
|
|
f, _, _, _ := cmdutil.TestFactory(t, &core.CliConfig{
|
|
AppID: "test-app",
|
|
AppSecret: "test-secret",
|
|
Brand: core.BrandFeishu,
|
|
})
|
|
return &ScopesOptions{
|
|
Factory: f,
|
|
Ctx: context.Background(),
|
|
Format: "json",
|
|
}
|
|
}
|
|
|
|
// TestAuthScopesRun_NetworkErrorPassedThrough pins that a typed NetworkError
|
|
// surfaced by the dependency is not re-classified as PermissionError —
|
|
// re-auth does not fix DNS / transport failures and blanket-wrapping them
|
|
// would mislead agents into infinite re-auth loops.
|
|
func TestAuthScopesRun_NetworkErrorPassedThrough(t *testing.T) {
|
|
netErr := errs.NewNetworkError(errs.SubtypeNetworkDNS, "DNS lookup failed")
|
|
stubGetAppInfoErr(t, netErr)
|
|
|
|
err := authScopesRun(scopesTestFactory(t))
|
|
if err == nil {
|
|
t.Fatal("expected error, got nil")
|
|
}
|
|
|
|
var permErr *errs.PermissionError
|
|
if errors.As(err, &permErr) {
|
|
t.Errorf("network failure must not be classified as PermissionError; got %v", permErr)
|
|
}
|
|
var gotNet *errs.NetworkError
|
|
if !errors.As(err, &gotNet) {
|
|
t.Fatalf("network failure not preserved through authScopesRun; got %T: %v", err, err)
|
|
}
|
|
if gotNet != netErr {
|
|
t.Errorf("typed network error should pass through identity-stable; got %p, want %p", gotNet, netErr)
|
|
}
|
|
}
|
|
|
|
// TestAuthScopesRun_PermissionErrorPassedThrough pins that typed permission
|
|
// failures from the dependency also pass through — IsTyped() must not single
|
|
// out one category.
|
|
func TestAuthScopesRun_PermissionErrorPassedThrough(t *testing.T) {
|
|
permErr := errs.NewPermissionError(errs.SubtypeMissingScope, "scope X missing").
|
|
WithMissingScopes("im:message")
|
|
stubGetAppInfoErr(t, permErr)
|
|
|
|
err := authScopesRun(scopesTestFactory(t))
|
|
if err == nil {
|
|
t.Fatal("expected error, got nil")
|
|
}
|
|
var got *errs.PermissionError
|
|
if !errors.As(err, &got) {
|
|
t.Fatalf("expected *PermissionError pass-through, got %T: %v", err, err)
|
|
}
|
|
if got != permErr {
|
|
t.Errorf("typed permission error should pass through identity-stable; got %p, want %p", got, permErr)
|
|
}
|
|
}
|
|
|
|
// TestAuthScopesRun_BareErrorWrappedAsInternal pins the unclassified branch:
|
|
// a bare error (e.g. json.Unmarshal failure inside getAppInfo) surfaces as
|
|
// *InternalError{SubtypeSDKError} with the original error preserved on
|
|
// Cause so errors.Is still walks to it.
|
|
func TestAuthScopesRun_BareErrorWrappedAsInternal(t *testing.T) {
|
|
bareErr := fmt.Errorf("failed to parse response: unexpected EOF")
|
|
stubGetAppInfoErr(t, bareErr)
|
|
|
|
err := authScopesRun(scopesTestFactory(t))
|
|
if err == nil {
|
|
t.Fatal("expected error, got nil")
|
|
}
|
|
|
|
var permErr *errs.PermissionError
|
|
if errors.As(err, &permErr) {
|
|
t.Errorf("bare getAppInfo error must not be classified as PermissionError; got %v", permErr)
|
|
}
|
|
|
|
var intErr *errs.InternalError
|
|
if !errors.As(err, &intErr) {
|
|
t.Fatalf("expected *InternalError, got %T: %v", err, err)
|
|
}
|
|
if intErr.Subtype != errs.SubtypeSDKError {
|
|
t.Errorf("InternalError.Subtype = %q, want %q", intErr.Subtype, errs.SubtypeSDKError)
|
|
}
|
|
if !errors.Is(err, bareErr) {
|
|
t.Error("InternalError must carry bareErr via WithCause so errors.Is walks to it")
|
|
}
|
|
}
|