logicsrc/packages/cli/src
Anthony Ettinger b1805d08e5
Some checks are pending
CI / build (push) Waiting to run
test / test (push) Waiting to run
Add SSH keys and config to credential sharing (#139)
* Add SSH keys and config to credential sharing

Private keys have lived as plaintext-on-disk files guarded only by a
passphrase. This puts them in the same end-to-end-encrypted vaults as
.env secrets, and adds an agent path so a machine can use a key without
ever writing one to its disk.

- `ssh` provider: ~/.ssh as a value bag. Files are picked by sniffing
  contents (PRIVATE KEY blocks, ssh-*/ecdsa-*/sk-* public keys) plus
  config, config.d/* and allowed_signers. known_hosts and
  authorized_keys are host-specific and access-granting, so they need
  an explicit --include.
- Each file is one secret carrying a JSON envelope of path, mode and
  body. The engine only hands write() the secrets that CHANGED, so a
  separate manifest secret would be absent whenever a key's contents
  change but the file list doesn't — self-describing values keep every
  restore total.
- `logicsrc secrets ssh push|pull|list|agent`, addressed by PERSON not
  project: the vault is ssh--<username>, which teams vaults reads as
  project ssh, env <username>. One teammate's keys never land in
  another's restore; sharing stays a deliberate teams grant.
- Both directions hold back anything that would overwrite a file that
  already differs, and say what they skipped. --force opts in. A
  restore onto a machine with its own keys is otherwise a way to lose
  them.
- Restores chmod each file back to its recorded mode; writeFileSync's
  mode applies only on create, so an existing world-readable key would
  otherwise stay world-readable. The adapter declares delete:false.
- push warns about passphrase-less private keys before they go up.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Add worked examples to secrets and secrets ssh help

Commander's usage line shows only the first alias, so `logicsrc secrets`
— the spelling people actually type — was invisible in its own help.
The examples carry it, alongside the flows worth copying: link/up/down,
the ssh backup round trip, and a plan → dry-run → approve sync.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Advertise the ssh provider on the marketing page

The marketing-drift contract failed the build because `ssh` shipped in the
provider registry with no entry in MARKETING_PROOF -- which is the test
working: it exists so a provider cannot ship while the pages people
actually land on still describe the tool without it.

The proof regex is `/~\/\.ssh|SSH key/` rather than a bare `/SSH/` on
purpose. The provider grid renders every registry `name`, and this one is
"Local SSH directory", so `/SSH/` would already be satisfied by the
generated grid and the provider could ship with no copy written about it
at all -- passing the test while failing its intent. Requiring the path or
the phrase means a human wrote a sentence.

That sentence is the new block in the credential-sharing band: ~/.ssh is a
directory of files whose permission bits are load-bearing, not a set of
KEY=VALUE lines, which is the part that makes this provider different from
the other six. README already named ~/.ssh keys, so it needed no change.

apps/logicsrc-web: 75/75 contract tests pass (was 74 passed, 1 failed).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-13 17:03:00 -07:00
..
config.test.ts fix(cli): block config prototype pollution (#54) 2026-06-13 22:52:20 -07:00
config.ts fix(credentials): one vault per user, in the config dir (#119) 2026-07-31 22:53:17 -07:00
context.ts Add the LogicSRC OpenContext specification (#132) 2026-08-09 11:46:11 -07:00
fixtures.ts Scaffold LogicSRC and CommandBoard plugins 2026-06-06 11:24:02 +00:00
format.ts Scaffold LogicSRC and CommandBoard plugins 2026-06-06 11:24:02 +00:00
index.test.ts Add feed discovery plugin 2026-06-09 09:34:31 +00:00
index.ts Add SSH keys and config to credential sharing (#139) 2026-08-13 17:03:00 -07:00
numeric-options.test.ts fix(cli): validate positive numeric options (#49) 2026-06-13 22:55:18 -07:00
numeric-options.ts fix(cli): validate positive numeric options (#49) 2026-06-13 22:55:18 -07:00
ontology.ts feat(openontology): Phase 2 + Phase 3 — storage, REST/SSE, MCP, RDF/SHACL, adapters, TUI, explorer (#101) 2026-07-28 05:10:33 -07:00
openspec.ts Implement OpenSpec artifacts and SDK contracts 2026-06-06 16:44:58 +00:00
prd.ts feat(openprd): implement the OpenPRD standard — engine, CLI, conformance bundle (#100) 2026-07-28 04:11:07 -07:00
registry.ts Add AgentBBS connector plugin (#131) 2026-08-04 18:43:31 -07:00
rotate.ts feat(credentials): re-key team vaults, and reach sh1pt's vault as a provider (#117) 2026-07-30 18:41:03 -07:00
secrets-link.test.ts feat(credentials): link directories to team secrets (#129) 2026-08-04 17:17:04 -07:00
secrets-link.ts feat(credentials): link directories to team secrets (#129) 2026-08-04 17:17:04 -07:00
ssh.test.ts Add SSH keys and config to credential sharing (#139) 2026-08-13 17:03:00 -07:00
ssh.ts Add SSH keys and config to credential sharing (#139) 2026-08-13 17:03:00 -07:00
teams.test.ts fix(cli): vault names join with "--", not "/" — the server rejects slashes (#112) 2026-07-30 13:32:07 -07:00
teams.ts Add SSH keys and config to credential sharing (#139) 2026-08-13 17:03:00 -07:00
update.test.ts fix(cli): make logicsrc update actually check for updates 2026-07-29 06:15:28 +00:00
update.ts fix(credentials): one vault per user, in the config dir (#119) 2026-07-31 22:53:17 -07:00