Repository navigation
OAuth2.1 doctl - #2012
OAuth2.1 doctl #2012anup-deka wants to merge 13 commits into
Conversation
d79815b to
6c4fb81
Compare
e5d0d37 to
3f44da8
Compare
213b906 to
a7a91f8
Compare
| Command: &cobra.Command{ | ||
| Use: "auth", | ||
| Short: "Display commands for authenticating doctl with an account", | ||
| Long: `The ` + "`" + `doctl auth` + "`" + ` commands allow you to authenticate doctl for use with your DigitalOcean account using tokens that you generate in the control panel at https://cloud.digitalocean.com/account/api/tokens. |
There was a problem hiding this comment.
When an OAuth token expires, doctl refreshes it automatically as part of starting up whatever command you’re running. The refresh then saves the config file — and the save writes out everything viper knows about, which includes all the flags you passed on that command line. So those flags get persisted and quietly become defaults for later runs.
Reproduction :
Start with a 10-line config.yaml with an expired token.
doctl --config ./config.yaml -u http://127.0.0.1:8765/ compute droplet list --region nyc1 --tag-name prod -o json
The refresh itself works. But config.yaml goes from 10 lines to 2,883, and now contains the api-url, the output format, and the region/tag-name filters.
Run again with no flags: doctl --config ./config.yaml compute droplet list
It still filters by tag_name=prod, and still points at the stub URL instead of the real API.
Fix:
On refresh, update only the auth keys rather than rewriting the whole config.
OAuth in Doctl