SpecsCLIM3-authenticated-distribution
M3 Issue Matrix: Authenticated Distribution
M3 Issue Matrix: Authenticated Distribution
Milestone
Linear milestone M3 Authenticated Distribution (b8f96d2f-1576-43a2-8f0e-a1e328aa73cf) covers Better Auth CLI access, backend-mediated baseline distribution, Vercel Blob artifact path, and required toolchain distribution.
Dependency Rules
- CLI architecture refactor is the prerequisite gate before M3 feature work.
IP-101andIP-103can proceed after the CLI refactor because auth/control-plane credential work and required-tool modeling can use disjoint write scopes.IP-102is blocked byIP-101; do not implement backend-mediated baseline distribution until the CLI auth path and bearer contract are usable.- GitHub stable and bundled baseline fallback behavior stays intact unless an accepted M3 requirement explicitly replaces it.
Issues
| ID | Title | State | Parent | Children | Blockers | Delivery order | Acceptance hints | URL |
|---|---|---|---|---|---|---|---|---|
| IP-101 | Add authenticated CLI access to internal baselines | Implemented in PR #4 | - | IP-122, IP-123 | CLI refactor | 2 | dp auth login; credential storage; dp auth status; dp auth logout; bearer calls from CLI to apps/api; public npm install remains separate from internal baseline access. | https://linear.app/devpunks/issue/IP-101/add-authenticated-cli-access-to-internal-baselines |
| IP-122 | CLI user can complete Better Auth login from terminal | Implemented in PR #4 | IP-101 | - | CLI refactor | 2a | Terminal command starts browser approval; CLI receives/stores runtime credential; status distinguishes auth state; logout clears local access. | https://linear.app/devpunks/issue/IP-122/cli-user-can-complete-better-auth-login-from-the-terminal |
| IP-123 | Authenticated CLI calls can reach apps/api | Implemented in PR #4 | IP-101 | - | IP-122 | 2b | CLI attaches credentials to typed backend calls; backend accepts valid authenticated requests; unauthorized baseline access returns typed error. | https://linear.app/devpunks/issue/IP-123/authenticated-cli-calls-can-reach-appsapi |
| IP-103 | Make the required harness toolchain explicit | Implemented in PR #4 | - | IP-126, IP-127 | CLI refactor | 3 | Required external tools modeled and checked: skills, opensrc, agent-browser, portless; portless is required, not optional; requirements visible in generated metadata. | https://linear.app/devpunks/issue/IP-103/make-the-required-harness-toolchain-explicit |
| IP-126 | CLI verifies required harness tools during setup | Implemented in PR #4 | IP-103 | - | CLI refactor | 3a | Setup checks skills, opensrc, agent-browser, and portless; missing tools produce clear operator guidance; tool requirements are represented in scaffold/backend metadata. | https://linear.app/devpunks/issue/IP-126/cli-verifies-required-harness-tools-during-setup |
| IP-127 | Internal dp-cli skill is provisioned through toolchain | Implemented in PR #4 | IP-103 | - | CLI refactor | 3b | skills can provide/verify dp-cli; setup/update exposes skill presence; skill includes CLI-backed issue reporting guidance. | https://linear.app/devpunks/issue/IP-127/internal-dp-cli-skill-is-provisioned-through-the-harness-toolchain |
| IP-102 | Distribute baselines through backend control plane | Implemented in PR #4 | - | IP-124, IP-125 | IP-101, IP-123 | 4 | Backend owns registry, provenance, authenticated artifact access, and adoption visibility; CLI still applies scaffold output locally. | https://linear.app/devpunks/issue/IP-102/distribute-baselines-through-the-backend-control-plane |
| IP-124 | CLI resolves recommended baseline through apps/api | Implemented in PR #4 | IP-102 | - | IP-101, IP-123 | 4a | Backend returns recommended baseline metadata for authenticated user; response includes compatibility/channel/provenance; CLI caches/applies resolved baseline locally. | https://linear.app/devpunks/issue/IP-124/cli-resolves-the-recommended-baseline-through-appsapi |
| IP-125 | Backend issues artifact access for baseline downloads | Implemented in PR #4 | IP-102 | - | IP-101, IP-123 | 4b | Backend issues signed/proxied baseline artifact URL; Vercel Blob evaluated as target; GitHub Releases can remain unprotected during migration. | https://linear.app/devpunks/issue/IP-125/backend-issues-artifact-access-for-baseline-downloads |
Evidence Status
- PR opened against
2.0.0: https://github.com/wearedevpunks/harness-intelligence/pull/4 - CLI refactor gate implemented and validated on branch
team/stefan/m3-delivery-20260514. - Current validation evidence:
git diff --check: passed.bun run check: passed.bun run check-types: passed 8 tasks.bun run test: passed 4 tasks, covering@punks/cli72 tests,@punks/api8 tests,@punks/scaffold4 tests, and@punks/contract3 tests.bun run build --filter=@punks/cli: passed.- Built CLI
--helpsmoke: passed. - Built CLI auth status/login/status/logout smoke with temp
DP_AUTH_CONFIG_FILE: passed.