app

package
v1.0.63 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 3, 2026 License: Apache-2.0 Imports: 103 Imported by: 0

Documentation

Overview

This file holds deliberate no-op stubs that act as edition-sync anchors for the private wukong edition overlay. The overlay replaces these function bodies with real host-compatibility configuration while the open-source build keeps them empty; both editions therefore share identical call sites (access_token_resolve.go, auth_command.go, doctor_command.go, force_refresh.go). These stubs are sync seams for the edition overlay, not dead code: do not delete them or their call sites during cleanup.

Index

Constants

View Source
const (
	// PatAuthRetryTimeout is the maximum time to wait for user authorization
	// when a PAT scope error is detected.
	PatAuthRetryTimeout = 10 * time.Minute

	// PatAuthPollInterval is how often we poll to check if the user has
	// completed authorization.
	PatAuthPollInterval = 5 * time.Second
)
View Source
const (
	// PerfDebugEnv is the environment variable to enable performance timing output.
	PerfDebugEnv = "DWS_PERF_DEBUG"

	// PerfReportEnv is the environment variable to enable JSON perf report output.
	// Set to "auto" to write to ~/.dws/perf/latest.json, or a custom file path.
	PerfReportEnv = "DWS_PERF_REPORT"
)

Variables

This section is empty.

Functions

func AppendDynamicServer added in v1.0.9

func AppendDynamicServer(server mcptypes.ServerDescriptor)

AppendDynamicServer adds a single server descriptor to the existing dynamic server registry without replacing the current entries. This is used by the plugin loader to inject plugin servers alongside Market-discovered servers.

func BuildTime added in v1.0.7

func BuildTime() string

BuildTime returns the timestamp injected via ldflags. Reproducible release recipes use the commit's committer time in UTC.

func ClearPluginAuth added in v1.0.54

func ClearPluginAuth(productID string)

ClearPluginAuth removes the ownership and credential record for a plugin product.

func CloseAuditSink added in v1.0.52

func CloseAuditSink()

CloseAuditSink flushes in-flight remote forwards and closes the audit writer. It is invoked from an unconditional defer in Execute so the drain happens for both successful and failed commands (Cobra skips PersistentPostRunE when RunE returns an error). The sync.Once makes repeated calls safe.

func CloseFileLogger

func CloseFileLogger()

CloseFileLogger flushes and closes the file logger.

func DirectRuntimeProductIDs

func DirectRuntimeProductIDs() map[string]bool

DirectRuntimeProductIDs returns product IDs that should stay visible for direct runtime execution. Dynamic products come from MCP discovery/plugin registration; built-in helper products such as devapp resolve their endpoint through DINGTALK_<PRODUCT>_MCP_URL instead of requiring discovery.

func Execute

func Execute() int

Execute runs the root command and returns the process exit code.

func ExecuteWithTelemetry added in v1.0.59

func ExecuteWithTelemetry() (exitCode int, commandPath string, errorMessage string)

ExecuteWithTelemetry runs the root command and additionally returns a privacy-safe command path and error summary for the official CLI entrypoint.

func FileLoggerInstance

func FileLoggerInstance() *slog.Logger

FileLoggerInstance returns the package-level file logger, or nil if not initialized.

func ForceRefreshAccessToken added in v1.0.16

func ForceRefreshAccessToken(ctx context.Context, configDir string) (string, error)

ForceRefreshAccessToken forces a single refresh_token exchange and returns the new access_token. It is intended for callers that have observed a server-side rejection (HTTP 401 or business code such as TOKEN_VERIFIED_FAILED) on what locally appeared to be a still-valid token.

It snapshots the current access token, then delegates to the OAuth provider's dual-locked compare-and-refresh operation. If another caller has already rotated the token, that newer token is reused without another refresh request.

func GitCommit added in v1.0.7

func GitCommit() string

GitCommit returns the git commit hash injected via ldflags.

func IsAuthRetrying added in v1.0.16

func IsAuthRetrying(ctx context.Context) bool

IsAuthRetrying reports whether the current context is already inside an AuthRefreshRequired retry. Mirrors IsPatRetrying.

func IsPatRetrying added in v1.0.11

func IsPatRetrying(ctx context.Context) bool

IsPatRetrying returns true if the current context is already in a PAT retry.

func IsPerfDebugEnabled added in v1.0.8

func IsPerfDebugEnabled() bool

IsPerfDebugEnabled returns true if performance debug output is enabled.

func IsStdioEndpoint added in v1.0.9

func IsStdioEndpoint(endpoint string) bool

IsStdioEndpoint returns true if the endpoint uses the stdio:// scheme.

func LookupStdioClient added in v1.0.9

func LookupStdioClient(productID string) (*transport.StdioClient, bool)

LookupStdioClient returns the StdioClient registered for the given product ID. The productID can be either the full key (pluginName/serverKey) or just the serverKey. This supports backward compatibility with existing CanonicalProduct values.

func MCPIdentityHeaders added in v1.0.9

func MCPIdentityHeaders() map[string]string

MCPIdentityHeaders returns the shared identity header map used by non-MCP transports such as the A2A gateway client. MCP-only Agent version and extension metadata are intentionally excluded.

func NewRootCommand

func NewRootCommand(ctx ...context.Context) *cobra.Command

NewRootCommand constructs the root CLI command. The provided context is propagated to background goroutines and the Cobra command tree so that SIGINT/SIGTERM can cancel in-flight work.

func NewRootCommandWithEngine

func NewRootCommandWithEngine(rootCtx context.Context, engine *pipeline.Engine) *cobra.Command

NewRootCommandWithEngine constructs the root CLI command with an optional pipeline engine for input correction. When engine is nil, no pipeline processing is applied.

func NewSchemaSourceRootCommand added in v1.0.54

func NewSchemaSourceRootCommand(ctx ...context.Context) *cobra.Command

NewSchemaSourceRootCommand constructs the distribution-owned command tree used as the Schema assembly source root (RegisterSchemaSourceRoot → ResolveSchemaBuild) and by command-surface policy. Installed plugins and user-defined shortcuts must not change the reviewed Schema surface. declarationOnly skips runtime profile selection, injectStaticServers and helpers.InitDeps so Schema assembly cannot clobber a live process's profile, ToolCaller or plugin endpoints.

func PrintPatAuthError added in v1.0.11

func PrintPatAuthError(w io.Writer, scopeErr *PatScopeError)

PrintPatAuthError prints a human-readable PAT authorization error.

func PrintPatAuthJSON added in v1.0.11

func PrintPatAuthJSON(w io.Writer, scopeErr *PatScopeError)

PrintPatAuthJSON prints a machine-readable PAT authorization error.

func RawVersion added in v1.0.7

func RawVersion() string

RawVersion returns the bare version string without build metadata.

func RecordNestedTiming added in v1.0.63

func RecordNestedTiming(ctx context.Context, name string, d time.Duration)

RecordNestedTiming records a diagnostic sub-phase without double-counting it when BuildReport derives framework overhead.

func RecordTiming added in v1.0.6

func RecordTiming(ctx context.Context, name string, d time.Duration)

RecordTiming is a convenience function to record timing to the collector in context.

func RegisterPluginAuth added in v1.0.9

func RegisterPluginAuth(productID string, auth *PluginAuth)

RegisterPluginAuth stores ownership and optional authentication credentials for a plugin server keyed by its canonical product ID.

func RegisterStdioClient added in v1.0.9

func RegisterStdioClient(productID string, client *transport.StdioClient)

RegisterStdioClient stores a StdioClient keyed by its canonical product ID (the CLI.ID used in the server descriptor). The runner looks up this client when a stdio:// endpoint is resolved at execution time.

func ResetRuntimeTokenCache added in v1.0.5

func ResetRuntimeTokenCache()

ResetRuntimeTokenCache clears the cached token, forcing a reload on next access. This should be called after login/logout operations.

func ResolveAuxiliaryAccessToken added in v1.0.9

func ResolveAuxiliaryAccessToken(ctx context.Context, configDir, explicitToken string) (string, error)

ResolveAuxiliaryAccessToken resolves every non-runner bearer token through the same TokenManager used by MCP tool calls.

func RunSchemaCacheBuilder added in v1.0.63

func RunSchemaCacheBuilder(args []string, output io.Writer) (bool, int)

RunSchemaCacheBuilder handles only the private declaration-builder process. It must run before normal root construction so plugin discovery is impossible.

func SanitizeCommand added in v1.0.9

func SanitizeCommand(args []string) string

SanitizeCommand redacts sensitive flag values from a command arg slice.

func SetDynamicServers

func SetDynamicServers(servers []mcptypes.ServerDescriptor)

SetDynamicServers injects server data discovered from servers.json. All product endpoints are resolved dynamically from this data.

func SetVersion added in v1.0.7

func SetVersion(v, bt, gc string)

SetVersion overrides the version, build time and git commit strings. Called by pkg/cli.SetVersion for overlay modules that inject their own version info via ldflags.

func StartTiming added in v1.0.6

func StartTiming(ctx context.Context, name string) func()

StartTiming is a convenience function that returns a stop function for defer usage. Example:

defer StartTiming(ctx, "operation")()

func StdioEndpoint added in v1.0.9

func StdioEndpoint(pluginName, serverKey string) string

StdioEndpoint returns a virtual endpoint URL for a stdio-based MCP server. Format: stdio://{pluginName}/{serverKey}

func StopAllStdioClients added in v1.0.10

func StopAllStdioClients()

StopAllStdioClients stops all registered stdio clients. This should be called on program exit to terminate child processes.

func StopStdioClient added in v1.0.10

func StopStdioClient(productID string) bool

StopStdioClient stops a specific stdio client by product ID. Returns true if the client was found and stopped, false otherwise.

func StopStdioClientsByPlugin added in v1.0.10

func StopStdioClientsByPlugin(pluginName string) int

StopStdioClientsByPlugin stops all stdio clients belonging to a plugin. The productID format is "pluginName/serverKey". This function stops all clients whose productID has the given pluginName prefix.

func Version

func Version() string

Version returns the current CLI version string, including build metadata when injected via ldflags (buildTime, gitCommit).

func WaitForPatAuthorization added in v1.0.11

func WaitForPatAuthorization(ctx context.Context, configDir string, output io.Writer) (bool, error)

WaitForPatAuthorization polls until the user completes authorization or timeout. It returns true if authorization was completed, false if timed out or cancelled.

func WithTimingCollector added in v1.0.6

func WithTimingCollector(ctx context.Context, tc *TimingCollector) context.Context

WithTimingCollector returns a new context with the TimingCollector attached.

Types

type AccessTokenSnapshot added in v1.0.54

type AccessTokenSnapshot struct {
	AccessToken      string
	ExpiresAt        time.Time
	Source           string
	LoginRegion      authpkg.LoginRegion
	LoginRegionKnown bool
}

AccessTokenSnapshot is the minimal bearer view needed by the process cache. Refresh-token material never leaves the auth package.

type CliSkillDTO added in v1.0.9

type CliSkillDTO struct {
	SkillID string `json:"skillId"`
	Name    string `json:"name"`
	Desc    string `json:"desc"`
	Icon    string `json:"icon"`
}

CliSkillDTO mirrors the old cli response payload for `skill search`.

type GlobalFlags

type GlobalFlags struct {
	ClientID     string
	ClientSecret string
	Debug        bool
	DryRun       bool
	Fields       string
	Format       string
	JQ           string
	Mock         bool
	Output       string
	Profile      string
	Timeout      int
	Token        string
	Verbose      bool
	Yes          bool
}

GlobalFlags contains the root-level persistent flags shared across the CLI.

type PatScopeError added in v1.0.11

type PatScopeError struct {
	OriginalError string
	Identity      string
	ErrorType     string
	Message       string
	Hint          string
	MissingScope  string
}

PatScopeError holds information about a missing PAT scope.

func (*PatScopeError) Error added in v1.0.11

func (e *PatScopeError) Error() string

type PerfPhase added in v1.0.9

type PerfPhase struct {
	Name       string `json:"name"`
	DurationMs int64  `json:"duration_ms"`
	Seq        int    `json:"seq"`
	Nested     bool   `json:"nested,omitempty"`
}

PerfPhase is a single phase in the performance report.

type PerfReport added in v1.0.9

type PerfReport struct {
	Kind       string      `json:"kind"`
	Version    string      `json:"version"`
	CLIVersion string      `json:"cli_version"`
	Command    string      `json:"command"`
	Timestamp  time.Time   `json:"timestamp"`
	TotalMs    int64       `json:"total_ms"`
	Phases     []PerfPhase `json:"phases"`
	Slowest    string      `json:"slowest"`
	OverheadMs int64       `json:"overhead_ms"`
}

PerfReport is the JSON-serialisable performance report.

func LoadLatestReport added in v1.0.9

func LoadLatestReport() (*PerfReport, error)

LoadLatestReport reads the default perf report file (~/.dws/perf/latest.json).

type PluginAuth added in v1.0.9

type PluginAuth struct {
	// Token is the Bearer token extracted from the plugin's
	// "Authorization" header (e.g. a third-party API key).
	Token string

	// ExtraHeaders contains any additional custom HTTP headers
	// declared by the plugin (excluding Authorization).
	ExtraHeaders map[string]string

	// TrustedDomains lists the hostnames that the token is allowed
	// to be sent to. Typically derived from the server endpoint.
	TrustedDomains []string
}

PluginAuth marks ownership of a plugin-owned streamable-http MCP server and holds its optional authentication credentials. Every accepted HTTP plugin, including an anonymous one, has a non-nil record keyed by canonical product ID (CLI.ID) so execution never falls back to built-in DingTalk OAuth.

func LookupPluginAuth added in v1.0.9

func LookupPluginAuth(productID string) (*PluginAuth, bool)

LookupPluginAuth returns plugin ownership and optional authentication credentials for the product ID. The bool denotes ownership, not whether a Bearer token is present.

type TelemetryIdentity added in v1.0.59

type TelemetryIdentity = clitelemetry.Identity

TelemetryIdentity is the privacy-reviewed subset of the local authentication record that may be attached to a CLI execution event.

func ResolveTelemetryIdentity added in v1.0.59

func ResolveTelemetryIdentity(args []string) (identity TelemetryIdentity)

ResolveTelemetryIdentity reads the identity selected by args. An asynchronous caller may omit a late result; concurrent login/logout can change the metadata observed during the read. Multi-profile executions use the current default profile. Resolution is deliberately best-effort: telemetry must not refresh credentials or change command behavior when local auth data is missing, invalid, or unreadable.

type TimingCollector added in v1.0.6

type TimingCollector struct {
	// contains filtered or unexported fields
}

TimingCollector collects timing measurements for a single command execution. It is safe for concurrent use.

func NewTimingCollector added in v1.0.6

func NewTimingCollector() *TimingCollector

NewTimingCollector creates a new collector with the start time set to now.

func TimingCollectorFromContext added in v1.0.6

func TimingCollectorFromContext(ctx context.Context) *TimingCollector

TimingCollectorFromContext extracts the TimingCollector from context, or nil.

func (*TimingCollector) BuildReport added in v1.0.9

func (tc *TimingCollector) BuildReport(cliVersion, command string) PerfReport

BuildReport constructs a PerfReport from the collected timing entries.

func (*TimingCollector) Entries added in v1.0.6

func (tc *TimingCollector) Entries() []TimingEntry

Entries returns a copy of all recorded entries in insertion order.

func (*TimingCollector) Print added in v1.0.6

func (tc *TimingCollector) Print(w io.Writer)

Print writes a summary of all timing entries to the given writer.

func (*TimingCollector) PrintIfEnabled added in v1.0.6

func (tc *TimingCollector) PrintIfEnabled()

PrintIfEnabled prints timing info to stderr if DWS_PERF_DEBUG is set.

func (*TimingCollector) Record added in v1.0.6

func (tc *TimingCollector) Record(name string, d time.Duration)

Record adds a timing entry with the given name and duration.

func (*TimingCollector) RecordNested added in v1.0.63

func (tc *TimingCollector) RecordNested(name string, d time.Duration)

RecordNested adds a diagnostic sub-phase. Nested phases are included in the report but excluded from overhead accounting because their duration is already covered by an enclosing top-level phase.

func (*TimingCollector) StartTimer added in v1.0.6

func (tc *TimingCollector) StartTimer(name string) func()

StartTimer returns a function that, when called, records the elapsed time since StartTimer was called. This is convenient for defer usage:

defer tc.StartTimer("operation")()

func (*TimingCollector) Total added in v1.0.6

func (tc *TimingCollector) Total() time.Duration

Total returns the total elapsed time since the collector was created.

func (*TimingCollector) WriteReportIfEnabled added in v1.0.9

func (tc *TimingCollector) WriteReportIfEnabled(cliVersion, command string)

WriteReportIfEnabled checks DWS_PERF_REPORT and writes a JSON report if set.

type TimingEntry added in v1.0.6

type TimingEntry struct {
	Name      string
	Duration  time.Duration
	Timestamp time.Time
	Seq       int // insertion order
	Nested    bool
}

TimingEntry represents a single timing measurement.

type TokenManager added in v1.0.54

type TokenManager struct {
	// contains filtered or unexported fields
}

TokenManager is the only process cache for user access tokens. Cache entries are isolated by config directory and profile, expiry-aware, and invalidated by the credential publication marker written by auth storage.

func NewTokenManager added in v1.0.54

func NewTokenManager() *TokenManager

func (*TokenManager) Get added in v1.0.54

func (m *TokenManager) Get(ctx context.Context, configDir, explicitToken string) (AccessTokenSnapshot, error)

Get resolves an access token for the active runtime profile.

func (*TokenManager) GetForProfile added in v1.0.62

func (m *TokenManager) GetForProfile(ctx context.Context, configDir, explicitToken, profile string) (AccessTokenSnapshot, error)

GetForProfile resolves an access token for one explicit profile without reading or mutating the process-wide runtime profile.

func (*TokenManager) Invalidate added in v1.0.54

func (m *TokenManager) Invalidate()

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL