P2: Add registry CLI discovery, input-file support and consistent write confirmation #838

Open
opened 2026-10-02 13:23:10 +00:00 by kayg · 1 comment
Owner

Research follow-up under #484. Source snapshot: c4a61e8cf090170f35b1bed3350d9de20c83ecd5.

The CLI already has global JSON, version 1 envelopes, exit codes 0–10, timeout/retry flags, local action discovery and a server-bound environment token. Keep those features.

Evidence in crates/calternal-cli/src/main.rs:

  • ActionCommand::Run accepts JSON only in --input; there is no generated input-file/stdin option.
  • ActionCommand::List exposes all supported operations without area/name filtering or a one-action explain command.
  • No shell completion command was found.
  • Generated mutations require --confirm, while legacy Rm, Mv, Share and other writes use a different rule.
  • login.rs:login still needs browser approval and can wait for five minutes; JSON does not provide a fast-fail non-interactive login mode.

Acceptance:

  1. Add file/stdin input through the same registry validation. Keep credentials out of command arguments and logs.
  2. Add discoverable area filtering, one-action help/examples and completion from the existing command/registry definitions.
  3. Make write confirmation semantics consistent and documented across legacy/generated commands; preserve non-interactive use of a pre-issued scoped credential.
  4. Provide an explicit non-interactive fast failure when interactive approval is needed. Do not invent authority or bypass fresh assertions.
  5. Keep stable JSON output, separated stderr and exit-code tests; preserve large streaming commands.

Related #484. Raw adapters already cover all 315 eligible routes; these are usability and safety gaps, not absent route coverage.

Full evidence and decisions: docs/research/agent-surfaces.md on branch job/research-surfaces. No runtime change was made by the research job.

Research follow-up under #484. Source snapshot: `c4a61e8cf090170f35b1bed3350d9de20c83ecd5`. The CLI already has global JSON, version 1 envelopes, exit codes 0–10, timeout/retry flags, local action discovery and a server-bound environment token. Keep those features. Evidence in `crates/calternal-cli/src/main.rs`: - `ActionCommand::Run` accepts JSON only in `--input`; there is no generated input-file/stdin option. - `ActionCommand::List` exposes all supported operations without area/name filtering or a one-action explain command. - No shell completion command was found. - Generated mutations require `--confirm`, while legacy `Rm`, `Mv`, `Share` and other writes use a different rule. - `login.rs:login` still needs browser approval and can wait for five minutes; JSON does not provide a fast-fail non-interactive login mode. Acceptance: 1. Add file/stdin input through the same registry validation. Keep credentials out of command arguments and logs. 2. Add discoverable area filtering, one-action help/examples and completion from the existing command/registry definitions. 3. Make write confirmation semantics consistent and documented across legacy/generated commands; preserve non-interactive use of a pre-issued scoped credential. 4. Provide an explicit non-interactive fast failure when interactive approval is needed. Do not invent authority or bypass fresh assertions. 5. Keep stable JSON output, separated stderr and exit-code tests; preserve large streaming commands. Related #484. Raw adapters already cover all 315 eligible routes; these are usability and safety gaps, not absent route coverage. Full evidence and decisions: `docs/research/agent-surfaces.md` on branch `job/research-surfaces`. No runtime change was made by the research job.
Author
Owner

Progress from job surfaces-p2 (branch job/surfaces-p2, commit a75e6f958). Not merged yet.

  • Discovery: action list --area/--search, action areas, action explain <id> (example input and command). completions <shell> covers the full tree.
  • Area commands generated from the registry: calternal action <area> <verb>, for every CLI action. Path params are positional; query, header and body fields are typed flags; the operation ID is an alias. Input still goes through Action::prepare. This gives #839–#843 their thin discoverable commands; the server-side intents (Make-a-Note, Mail save-to-Home, server behavior preference) are not in this slice.
  • Input: --input JSON|@FILE|- and --input-file FILE|-, one 128 KiB bound and one validator.
  • Confirmation: one documented rule. Registry writes need the global --confirm (exit 2, checked before credentials or network); --dry-run prints the exact request offline. Named recoverable commands stay as they are; named permanent removals (calendar feed-remove, feed-revoke, subscription-remove) now need --confirm.
  • login --non-interactive checks the existing credential and fails at once with exit 3 instead of waiting for browser approval.
  • Docs: docs/action-registry.md CLI section.
Progress from job surfaces-p2 (branch `job/surfaces-p2`, commit a75e6f958). Not merged yet. - Discovery: `action list --area/--search`, `action areas`, `action explain <id>` (example input and command). `completions <shell>` covers the full tree. - Area commands generated from the registry: `calternal action <area> <verb>`, for every CLI action. Path params are positional; query, header and body fields are typed flags; the operation ID is an alias. Input still goes through `Action::prepare`. This gives #839–#843 their thin discoverable commands; the server-side intents (Make-a-Note, Mail save-to-Home, server behavior preference) are not in this slice. - Input: `--input JSON|@FILE|-` and `--input-file FILE|-`, one 128 KiB bound and one validator. - Confirmation: one documented rule. Registry writes need the global `--confirm` (exit 2, checked before credentials or network); `--dry-run` prints the exact request offline. Named recoverable commands stay as they are; named permanent removals (`calendar feed-remove`, `feed-revoke`, `subscription-remove`) now need `--confirm`. - `login --non-interactive` checks the existing credential and fails at once with exit 3 instead of waiting for browser approval. - Docs: `docs/action-registry.md` CLI section.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#838
No description provided.