Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 9 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -451,6 +451,15 @@ process sends, in the same `k1=v1&k2=v2` shape as a URL's own query string —
for an API parameter this CLI's specs don't declare a flag for. `--debug`
and `--dry-run` show it alongside everything else on the request.

### The CLI's own requests

Requests the CLI makes for itself rather than for your commands use your own
token whenever you have one: `--token` or `MAPBOX_ACCESS_TOKEN`, then your
login. Only when you have none does it use the CLI's token:
`MAPBOX_CLI_TOKEN`, or one built into the binary. The CLI's token is only
ever sent to the few Mapbox APIs listed for it in `src/cli_token.rs`, today
just telemetry.

### Proxies

`HTTPS_PROXY`, `HTTP_PROXY`, `ALL_PROXY` and `NO_PROXY` are all honored, so
Expand Down
16 changes: 16 additions & 0 deletions build.rs
Original file line number Diff line number Diff line change
Expand Up @@ -41,6 +41,8 @@
use std::path::Path;

fn main() {
check_bundled_token();

let manifest = Path::new("../internal/openapi-command-config/PINNED_SOURCE");

// The vendored specs and their provenance are ordinary build inputs now,
Expand Down Expand Up @@ -91,6 +93,20 @@ fn main() {
warn_if_stale(committed_at);
}

/// `src/cli_token.rs` compiles `MAPBOX_CLI_BUNDLED_TOKEN` into the binary,
/// where `strings` can read it. Only a public `pk.` token may go there, so
/// anything else fails the build rather than shipping a secret.
fn check_bundled_token() {
println!("cargo:rerun-if-env-changed=MAPBOX_CLI_BUNDLED_TOKEN");
let Ok(token) = std::env::var("MAPBOX_CLI_BUNDLED_TOKEN") else {
return;
};
let token = token.trim();
if !token.is_empty() && !token.starts_with("pk.") {
panic!("MAPBOX_CLI_BUNDLED_TOKEN must be a public pk. token");
}
}

/// New API surface lands in `openapi-specs` at something closer to a monthly
/// rate, and the maintainer-only sync that regenerates `openapi/` from it
/// runs weekly, so two weeks without one is already long enough to be worth a
Expand Down
5 changes: 3 additions & 2 deletions src/auth.rs
Original file line number Diff line number Diff line change
Expand Up @@ -479,8 +479,9 @@ fn credentials_path_readonly(profile: Option<&str>) -> Option<PathBuf> {
/// directory as a side effect of reading it — see
/// [`credentials_path_readonly`]. What [`profiles`] reads each stored
/// profile through, since listing what exists must not be the reason a
/// directory starts to exist or its permissions change.
fn load_credentials_readonly(profile: Option<&str>) -> Option<Credentials> {
/// directory starts to exist or its permissions change, and what
/// [`crate::cli_token`] reads the login through for the same reason.
pub(crate) fn load_credentials_readonly(profile: Option<&str>) -> Option<Credentials> {
let data = std::fs::read_to_string(credentials_path_readonly(profile)?).ok()?;
serde_json::from_str(&data).ok()
}
Expand Down
Loading
Loading