Skip to content

feat: add non-persistent env-based authentication mode - #1692

Merged
developerkunal merged 3 commits into
mainfrom
feat/env-auth-mode
Sep 30, 2026
Merged

developerkunal merged 3 commits into
mainfrom
feat/env-auth-mode

Conversation

@developerkunal

Copy link
Copy Markdown
Contributor

🔧 Changes

Adds AUTH0_CLI_AUTH_MODE=env, an opt-in credential source for agents, CI, and sandboxes that cannot use the OS keychain or write to ~/.config/auth0. Today those environments fail because the CLI assumes it can read a keychain token and persist tenant config; this gives them a first-class, non-persistent path.

  • New env auth mode. When AUTH0_CLI_AUTH_MODE=env, the CLI authenticates from AUTH0_DOMAIN plus either AUTH0_API_TOKEN (used directly) or AUTH0_CLIENT_ID/AUTH0_CLIENT_SECRET (exchanged for a token). The token is held in memory for the command only. No config or keychain read/write happens in this mode. It must be opted into explicitly, since those AUTH0_* vars are also read by the Terraform provider and sample apps, so their mere presence must never silently replace a saved login or switch tenants. An unrecognized mode value is rejected instead of silently falling back.
  • Accurate error when the stored token is unreadable. A keychain that cannot be read (as in a sandbox) previously surfaced as session_expired, suggesting a re-login that would not help. It now reports a distinct stored_token_unavailable, while a genuinely expired token still reports session_expired. The existing inline-config token fallback is preserved.
  • Domain validation before any token request. AUTH0_DOMAIN is validated as a bare host name, and the shared client-credentials exchange rejects a domain that does not parse back to itself. This closes a path where a value carrying userinfo (for example tenant.example@evil.example) would send the client secret to another host.
  • Config-independence fixes for env mode. Commands that built dashboard URLs, saved a default app (apps use, apps create), selected an app interactively, or read the install ID for tracking no longer depend on saved config in env mode. open-style commands now return a tagged error when they genuinely cannot build a URL instead of exiting 0 with no output.

🔬 Testing

  • make test-unit, go vet ./..., and make lint (changed packages) all pass. make docs produces no changes (no command or flag surface changed).
  • New unit tests cover mode validation, domain-host validation (including userinfo and port rejection), the shared exchange rejecting an unsafe domain, tenant/--tenant conflict handling, env setup with no saved config, tracking skipping disk reads in env mode, and apps use rejection in env mode.
  • Manually verified end to end with the built binary: env mode with a bare domain reaches the Management API and writes nothing to disk; missing/invalid domain, a --tenant conflict, and a userinfo domain all fail before any network call with the correct tagged errors; saved-login commands are unchanged.

📝 Checklist

  • All new/changed/fixed functionality is covered by tests (or N/A)
  • I have added documentation for all new/changed functionality (or N/A)

Add AUTH0_CLI_AUTH_MODE=env as an opt-in credential source for agents,
CI, and sandboxes that cannot use the OS keychain or write config. In
this mode the CLI authenticates from AUTH0_DOMAIN plus either
AUTH0_API_TOKEN or AUTH0_CLIENT_ID/AUTH0_CLIENT_SECRET, holds the token
in memory only, and never reads or writes the on-disk config or keychain.

Distinguish an unreadable stored token from an expired one with a
dedicated stored_token_unavailable error, so keychain-inaccessible
environments get an accurate, actionable message instead of a misleading
session_expired.

Validate AUTH0_DOMAIN as a bare host before any token request so a value
carrying userinfo cannot redirect a client-credentials exchange, and its
client secret, to another host.
@developerkunal
developerkunal requested a review from a team as a code owner September 29, 2026 18:50
When the keychain is locked, the config is not writable, or there is no
saved login, and usable AUTH0_* credentials are already in the environment,
point non-interactive callers at enabling AUTH0_CLI_AUTH_MODE=env instead of
only reporting the failure. This stays a hint rather than an auto-switch, so
the presence of the shared AUTH0_* vars never changes auth on its own.

Also tighten the verbose explanatory comments across the env-auth changes.
@developerkunal
developerkunal merged commit a1b2884 into main Sep 30, 2026
6 checks passed
@developerkunal
developerkunal deleted the feat/env-auth-mode branch September 30, 2026 10:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants