Skip to content

Preserve CLI recovery data and report unavailable monitor checks - #97

Merged
adamXbot merged 3 commits into
mainfrom
codex/cli-recovery-audit
Oct 1, 2026
Merged

adamXbot merged 3 commits into
mainfrom
codex/cli-recovery-audit

Conversation

@adamXbot

@adamXbot adamXbot commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

Summary

Fix CLI reliability and recovery findings from the latest surface audit.

  • Keep unavailable/error monitor states visible with --tripped-only, exit unsuccessfully for incomplete checks, validate response bodies, and include configured Cloudflare Access credentials. Intentional 503 tripped responses remain supported.
  • Fetch every page for list --all.
  • Preserve shared server credentials while another profile references them; align profile removal and logout wording with the actual effect.
  • Include configured Access authentication when verifying login/API-key rotation on the same server; do not forward old profile credentials when its URL changes.
  • Check bulk CSV output before creation, sync completed mappings to a private recovery journal, retain it after output failures, and drain in-flight requests when interrupted.
  • Report confirmed keys and an idempotent resume command after partial device setup.

Verification

  • Full CLI suite: 170 tests passed with two workers; CLI typecheck and whitespace checks passed.
  • Regression coverage includes failed/malformed statuses, legitimate 503 tripped states, more than 1,000 keys, shared credentials, Access-aware authentication and cross-server isolation, bulk output failure/interruption including final CSV flushing, and partial device recovery.
  • Branch includes the merged Fix remaining CLI and dashboard experience issues #93/Clear production dependency audit #94 fixes and refreshed security dependencies.
  • Fresh CI covers all package types, server/CLI/edge tests, PostgreSQL integration, production build, CLI artifact, dependency audit, and security analysis.

Recovery limits

If a non-idempotent bulk request fails without returning a key, it may already have completed remotely. The command tells the operator to inspect the server before retrying. Real OS keychain, Cloudflare login, and host installation were not exercised locally.

@adamXbot
adamXbot merged commit 83c3096 into main Oct 1, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant