Skip to content

Support configurable TOTP in credential commands - #277

Merged
masnwilliams merged 2 commits into
mainfrom
hypeship/totp-cli
Oct 1, 2026
Merged

masnwilliams merged 2 commits into
mainfrom
hypeship/totp-cli

Conversation

@masnwilliams

@masnwilliams masnwilliams commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Add TOTP algorithm, digits, and period flags to credential create/update.
  • Use typed Go SDK v0.116.0 request fields; preserve omitted values on updates.
  • Document provisioning URI input and remove the six-digit assumption from code help.

Checks

  • go test ./... passed locally.

@masnwilliams
masnwilliams requested a review from akxue October 1, 2026 18:59
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedgolang/​github.com/​kernel/​kernel-go-sdk@​v0.114.1-0.20260930182635-e746d9980b83 ⏵ v0.116.073 +1100100100100

View full report

@akxue akxue left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good! comments are around help text and making the new totp flags a bit clearer. additionally, as a note, get/create don't output the new totp settings

  • cmd/credentials.go:496-497 — on credentials update --help, --totp-digits and --totp-period show (6) / (30), which reads like leaving them off sets 6/30. the API actually keeps whatever's already stored when you rotate a base32 secret. maybe register these with default 0 so the default isn't printed, and add a line saying omitted settings are kept? (on create the help also prints (default 6) (6) since cobra appends the default automatically)
  • cmd/credentials.go:185-206 — if --totp-secret is an otpauth:// URI that has its own digits/algorithm/period, the API uses the URI's values and silently ignores the --totp-* flags. i think we should warn here rather than reject
  • cmd/credentials.go:165-175, cmd/credentials.go:268-278 — note: get/create only print Has TOTP Secret: Yes, so there's no way to confirm which algorithm/digits/period got stored. the sdk response includes these now, so they could be added as rows

@masnwilliams
masnwilliams merged commit 53119d1 into main Oct 1, 2026
8 checks passed
@masnwilliams
masnwilliams deleted the hypeship/totp-cli branch October 1, 2026 21:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants