Skip to content

Commit 4cb135d

Browse files
authored
Require project IDs for CLI request scoping (#218)
## Summary - document the global `--project` flag as accepting project IDs only - use the Go SDK's typed `option.WithProjectID` client option - align `KERNEL_PROJECT` examples with the merged API contract ## Why `X-Kernel-Project-Id` is an ID selector on the merged API. Advertising project names here can scope a command incorrectly or produce a confusing not-found response. The typed SDK option also keeps client configuration aligned with generated SDK behavior. ## Implementation The request still carries the same `X-Kernel-Project-Id` header. This changes the public CLI guidance and replaces the manually named header option with the SDK's first-class project option. ## Verification - `go test -short -timeout=2m ./...` - `go vet ./...` - `gofmt -l cmd` - `git diff --check` - crap4go: changed `resolveProjectSelection` CRAP 2.0; root `init` CRAP 5.8 <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Low Risk** > Small client-option refactor with equivalent header behavior; main user-facing change is clearer docs that names are not valid for global scoping. > > **Overview** > **Global project scoping** (`--project` / `KERNEL_PROJECT`) is now documented and intended for **project IDs only**, not names, matching the API’s `X-Kernel-Project-Id` contract. > > Client setup switches from a manual `X-Kernel-Project-Id` header option to the Go SDK’s **`option.WithProjectID`** (same header, typed configuration). README and flag help text are updated accordingly, including clarification that **`api-keys create --project-id`** is separate from the global scoping flag. Tests use ID-style example values. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 8f4d57d. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY -->
1 parent 3c77a11 commit 4cb135d

3 files changed

Lines changed: 8 additions & 7 deletions

File tree

‎README.md‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -103,6 +103,7 @@ Create an API key from the [Kernel dashboard](https://dashboard.onkernel.com).
103103
- `--version`, `-v` - Print the CLI version
104104
- `--no-color` - Disable color output
105105
- `--log-level <level>` - Set log level (trace, debug, info, warn, error, fatal, print)
106+
- `--project <project-id>` - Scope requests to a project ID (or set `KERNEL_PROJECT` to a project ID)
106107

107108
## JSON Output
108109

@@ -622,7 +623,7 @@ Automated authentication for web services. The `run` command orchestrates the fu
622623
- `kernel api-keys create` - Create a new API key
623624
- `--name <name>` - API key name (required)
624625
- `--days-to-expire <days>` - Number of days until expiry (1-3650); omit for never
625-
- `--project-id <project_id>` - Create a project-scoped API key for this project ID; omit for org-wide. This is different from global `--project`, which only scopes the CLI request.
626+
- `--project-id <project_id>` - Create a project-scoped API key for this project ID; omit for org-wide. This is different from global `--project`, which scopes the CLI request to a project ID.
626627
- `--output json`, `-o json` - Output raw JSON object, including the one-time plaintext key
627628

628629
- `kernel api-keys list` - List API keys

‎cmd/root.go‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -116,7 +116,7 @@ func init() {
116116
rootCmd.PersistentFlags().BoolP("version", "v", false, "Print the CLI version")
117117
rootCmd.PersistentFlags().BoolP("no-color", "", false, "Disable color output")
118118
rootCmd.PersistentFlags().String("log-level", "warn", "Set the log level (trace, debug, info, warn, error, fatal, print)")
119-
rootCmd.PersistentFlags().String("project", "", "Project ID or name to scope all requests to (or set KERNEL_PROJECT env var)")
119+
rootCmd.PersistentFlags().String("project", "", "Project ID to scope all requests to (or set KERNEL_PROJECT to a project ID)")
120120
rootCmd.SilenceUsage = true
121121
rootCmd.SilenceErrors = true
122122
cobra.OnInitialize(initConfig)
@@ -143,7 +143,7 @@ func init() {
143143
projectVal = resolveProjectSelection(projectVal)
144144

145145
if projectVal != "" {
146-
clientOpts = append(clientOpts, option.WithHeader("X-Kernel-Project-Id", projectVal))
146+
clientOpts = append(clientOpts, option.WithProjectID(projectVal))
147147
}
148148

149149
client, err := auth.GetAuthenticatedClient(clientOpts...)

‎cmd/root_test.go‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -80,13 +80,13 @@ func TestIsAuthExempt(t *testing.T) {
8080

8181
func TestResolveProjectSelection(t *testing.T) {
8282
t.Run("flag value wins over env var", func(t *testing.T) {
83-
t.Setenv("KERNEL_PROJECT", "env-project")
84-
assert.Equal(t, "flag-project", resolveProjectSelection("flag-project"))
83+
t.Setenv("KERNEL_PROJECT", "env-project-id")
84+
assert.Equal(t, "flag-project-id", resolveProjectSelection("flag-project-id"))
8585
})
8686

8787
t.Run("env var used when no flag", func(t *testing.T) {
88-
t.Setenv("KERNEL_PROJECT", "env-project")
89-
assert.Equal(t, "env-project", resolveProjectSelection(""))
88+
t.Setenv("KERNEL_PROJECT", "env-project-id")
89+
assert.Equal(t, "env-project-id", resolveProjectSelection(""))
9090
})
9191

9292
t.Run("empty when no flag or env var", func(t *testing.T) {

0 commit comments

Comments
 (0)