fix(cli): require interactive purchase confirmation - #2125
Merged
Merged
Conversation
Remove the --yes bypass from both purchase coordinators while preserving unattended dry runs. Cover flag rejection, nonterminal refusal and dry-run reports, and update the purchase-safety reference. Closes #1943
Contributor
|
Warning Review limit reached
This review includes 10 billable files and costs up to $2.50.
Reviews can continue after your included limit without a manual trigger. An admin must approve usage-based billing. Or wait 17 minutes for your next included review. View limit detailsLimit details: You’ve used the included review currently available. Your 68 included PR review attempts over the past 7 days set your current allowance at 1 review per hour. Review configuration: ⚙️ Run configurationConfiguration used: Repository: LeanerCloud/cloud-commitments-cli/.coderabbit.yaml Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (10)
Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Removes the
--yesflag and its confirmation bypass. Both AWS purchase paths now require an affirmative terminal response once for the whole run; nonterminal stdin is refused even when it containsyes. Unattended dry runs retain their reports and audit records. Existing commands with--yesare rejected during parsing.Closes #1943.
Validation: the flag regression fails on the original code and passes after the fix. The full race suite passed, followed by focused race checks after test-only review corrections. Build, vet, golangci-lint 2.10.1 and normal commit hooks passed. Local pseudo-terminal checks drove the actual prompt and both coordinators: yes/y produced two successful fake SDK purchases, no/EOF produced none, and removed-flag CLI invocations reached no provider. These were local fake-provider scenarios with synthetic credentials, not cloud purchases.
The terminal prompt is an operator safeguard, not a security boundary against software that can control a terminal.
Independent gpt-6-astra review approved commit
2c6f21a00cab38b21baa748326f15b686a140b1dafter two source-review passes and final runtime verification in a separate clone. The reviewer independently passed focused race tests (7.436s), build, and all 16 local PTY/coordinator/CLI checks; restoring the original flag registration made the regression fail at the intended assertion. Required CI remains a merge gate. Local review substitutes for CodeRabbit under the session authorization.