SpecsCLIM3-authenticated-distribution
Implementation Notes: M3 Authenticated Distribution
Implementation Notes: M3 Authenticated Distribution
2026-05-14
PR
- Ready PR opened against
2.0.0: https://github.com/wearedevpunks/harness-intelligence/pull/4 - Branch:
team/stefan/m3-delivery-20260514
Inventory
- M3 milestone:
M3 Authenticated Distribution - Parents:
IP-101,IP-102,IP-103 - Children:
IP-122,IP-123,IP-124,IP-125,IP-126,IP-127 - Dependency order: CLI refactor -> IP-101/IP-103 -> IP-102
CLI Refactor Gate
- Added shared command helper
apps/cli/src/cli/baseline-options.ts. - Extracted required-tool installation/checking into
apps/cli/src/core/tools.ts. - Added direct boundary tests in
apps/cli/src/core/tools.test.ts. - Updated scaffold/update runners to import required-tool behavior from
core/toolsinstead ofscaffold/run.
Validation
bun run test --filter=@punks/cli --filter=@punks/api: passed@punks/cli71 tests and@punks/api4 tests.bun run check-types --filter=@punks/cli --filter=@punks/api --filter=@punks/auth: passed 6 tasks.bun run check-types --filter=@punks/api --filter=@punks/cli: passed 4 tasks after IP-102 registry work.bun run test --filter=@punks/api: passed 6 tests after IP-102 registry work.bun run build --filter=@punks/cli: passed.DP_NO_UPDATE_CHECK=1 DP_NO_SKILL_UPDATE_CHECK=1 bun apps/cli/dist/index.js --help: passed and listsauthcommands.punks auth status -> login --token -> status -> logoutagainst a tempDP_AUTH_CONFIG_FILE: passed.git diff --check: passed.bun run check: passed after formatting generated scaffolded harness agent files.
IP-101 / IP-122 / IP-123
- Added
punks auth login/status/logout. - Added Better Auth device authorization client for
POST /device/codeandPOST /device/token. - Added local-development
--tokenlogin path for credential-unavailable environments. - Stored credentials are read by baseline control-plane resolution when
DP_CONTROL_PLANE_TOKENis absent. - Enabled Better Auth
bearer()anddeviceAuthorization()plugins inpackages/auth. - API bearer auth rejects missing/invalid credentials, fails closed when
DP_API_CLI_TOKENis absent, accepts explicitly configured local-development static tokens, and delegates real session bearers to Better Auth. /api/auth/*is routed to Better Auth so device authorization endpoints are available alongside the typed Harness API.- Better Auth device authorization storage is modeled in
packages/dbthrough thedevice_codetable. - Device-token polling handles OAuth
authorization_pendingandslow_downerrors returned as HTTP 400 bodies.
IP-103 / IP-126 / IP-127
- Base required tools are now
agent-browser,opensrc,portless, andskills. - Content tests pin the base required-tool set and selected-skill additions.
- Existing
dp-cliskill startup verification remains advisory and non-blocking during command startup; setup/update now keepskillsin the base toolchain and docs/runbook explain the provisioning path.
IP-102 / IP-124 / IP-125
- Added
apps/api/src/baseline-registry.ts. - Authenticated baseline resolution reads backend-owned metadata from
DP_BASELINE_*environment variables. - Authenticated artifact metadata endpoint returns backend-issued manifest/archive URLs and checksums.
- Unconfigured backend metadata still returns
ControlPlaneUnavailable, preserving CLI fallback behavior. - Vercel Blob is recorded as compatible with the artifact URL boundary; M3 keeps URLs storage-provider agnostic so GitHub Release assets can remain usable during migration.
Notes
bun installwas required because the worktree had nonode_modules; generated unrelatedbun.lockdrift was restored.- Pre-existing
.codex/config.tomldrift is preserved and unrelated to this implementation.
Review Fixes
- Review found three high-severity blockers: API auth failed open to a documented default token, device polling could not handle Better Auth pending errors, and Better Auth device storage/routes were not wired.
- Fixed by removing the default API token, mounting Better Auth routes, adding device-code schema support, and parsing device-token error bodies before deciding poll state.
- Focused validation after fixes:
bun run test --filter=@punks/api --filter=@punks/cli: passed@punks/api8 tests and@punks/cli72 tests.bun run check-types --filter=@punks/api --filter=@punks/cli --filter=@punks/auth --filter=@punks/db: passed 6 tasks.
Docs Ingest
- Updated CLI bearer-auth concept and routed page.
- Updated control-plane baseline-resolution flow and routed page.
- Existing
docs/README.mdanddocs/runbooks/dp-cli-scaffolding.mdwere updated with auth, baseline registry, and required-toolchain operator guidance.
Final Validation
git diff --check: passed.bun run check: passed after formatting generated agent context files.bun run check-types: passed 8 tasks.bun run test: passed 4 tasks.bun run build --filter=@punks/cli: passed.- Built CLI
--help: passed. - Built CLI auth status/login/status/logout smoke with a temp
DP_AUTH_CONFIG_FILE: passed.
PR Review Debt
- Resolved Codex PR review finding:
punks auth loginno longer falls back toDP_CONTROL_PLANE_URLfor Better Auth device-login endpoints. - Resolved Codex PR review finding: browser auto-open failure now prints manual guidance and continues device-token polling.
- Debt record:
docs/reference/tech-debt/cli/M3-authenticated-distribution/pr-4-auth-login-review-findings.md. - Validation:
bun run test --filter=@punks/cli: passed 75 tests.bun run check-types --filter=@punks/cli: passed 3 tasks.bun run check: passed.git diff --check: passed.bun run build --filter=@punks/cli: passed.- Built CLI
auth login --help: passed.
PR Review Auth Hardening Debt
- Resolved Codex PR review finding: empty
--auth-urlandDP_AUTH_URLvalues now normalize to missing auth configuration. - Resolved Codex PR review finding: malformed stored auth credentials now read as unauthenticated instead of crashing status or baseline credential lookup.
- Debt record:
docs/reference/tech-debt/cli/M3-authenticated-distribution/pr-4-auth-hardening-review-findings.md. - Validation:
bun run test --filter=@punks/cli: passed 77 tests.bun run check-types --filter=@punks/cli: passed 3 tasks.bun run check: passed.git diff --check: passed.bun run build --filter=@punks/cli: passed.- Built CLI
auth login --help: passed.
PR Review Empty Configuration Debt
- Resolved Codex PR review finding: blank
punks auth login --tokenvalues now normalize to missing local-development tokens instead of persisting unusable credentials. - Resolved Codex PR review finding: empty
DP_BASELINE_*values now make the backend baseline registry unavailable instead of returning blank metadata. - Debt record:
docs/reference/tech-debt/cli/M3-authenticated-distribution/pr-4-empty-config-review-findings.md. - Validation:
bun run test --filter=@punks/cli --filter=@punks/api: passed@punks/cli78 tests and@punks/api9 tests.bun run check-types --filter=@punks/cli --filter=@punks/api: passed 6 tasks.bun run check: passed.git diff --check: passed.bun run build --filter=@punks/cli: passed.- Built CLI
auth login --help: passed. - Built CLI
auth login --token "": failed with the intended non-empty token error and did not store credentials.
PR Review Device Flow Debt
- Resolved Codex PR review finding: Better Auth now advertises the served
/api/auth/deviceverification route instead of the unmounted/devicepath. - Resolved Codex PR review finding: CLI device-token polling now honors the server-issued device-code
expires_inlifetime instead of always timing out after five minutes. - Debt record:
docs/reference/tech-debt/cli/M3-authenticated-distribution/pr-4-device-flow-review-findings.md. - Validation:
bun run test --filter=@punks/cli --filter=@punks/api: passed@punks/cli79 tests and@punks/api10 tests.bun run check-types --filter=@punks/cli --filter=@punks/api --filter=@punks/auth: passed 6 tasks.bun run check: passed.git diff --check: passed.bun run build --filter=@punks/cli: passed.- Built CLI
auth login --help: passed. bun run test: passed 4 tasks.bun run check-types: passed 8 tasks.