Skip to content

OAuth2.1 doctl - #2012

Open
anup-deka wants to merge 13 commits into
mainfrom
digitalocean-oauth-doctl
Open

anup-deka wants to merge 13 commits into
mainfrom
digitalocean-oauth-doctl

Conversation

@anup-deka

Copy link
Copy Markdown
Contributor

OAuth in Doctl

Comment thread internal/oauth/login.go Outdated
@anup-deka
anup-deka force-pushed the digitalocean-oauth-doctl branch from d79815b to 6c4fb81 Compare October 8, 2026 12:28
@anup-deka
anup-deka force-pushed the digitalocean-oauth-doctl branch from e5d0d37 to 3f44da8 Compare October 8, 2026 12:42
@anup-deka
anup-deka force-pushed the digitalocean-oauth-doctl branch from 213b906 to a7a91f8 Compare October 8, 2026 14:52
Comment thread commands/auth.go
Command: &cobra.Command{
Use: "auth",
Short: "Display commands for authenticating doctl with an account",
Long: `The ` + "`" + `doctl auth` + "`" + ` commands allow you to authenticate doctl for use with your DigitalOcean account using tokens that you generate in the control panel at https://cloud.digitalocean.com/account/api/tokens.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

When an OAuth token expires, doctl refreshes it automatically as part of starting up whatever command you’re running. The refresh then saves the config file — and the save writes out everything viper knows about, which includes all the flags you passed on that command line. So those flags get persisted and quietly become defaults for later runs.

Reproduction :

Start with a 10-line config.yaml with an expired token.
doctl --config ./config.yaml -u http://127.0.0.1:8765/ compute droplet list --region nyc1 --tag-name prod -o json
The refresh itself works. But config.yaml goes from 10 lines to 2,883, and now contains the api-url, the output format, and the region/tag-name filters.
Run again with no flags: doctl --config ./config.yaml compute droplet list
It still filters by tag_name=prod, and still points at the stub URL instead of the real API.

Fix:
On refresh, update only the auth keys rather than rewriting the whole config.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants