Skip to content

cedric/switch local asked nonexistant before network call#284

Draft
Cedric / ViaDézo1er (viadezo1er) wants to merge 16 commits into
mainfrom
cedric/switch-local-asked-nonexistant-before-network-call
Draft

cedric/switch local asked nonexistant before network call#284
Cedric / ViaDézo1er (viadezo1er) wants to merge 16 commits into
mainfrom
cedric/switch-local-asked-nonexistant-before-network-call

Conversation

@viadezo1er

@viadezo1er Cedric / ViaDézo1er (viadezo1er) commented Jul 24, 2026

Copy link
Copy Markdown
Contributor
  • chore(switch): network call happens after options validation
    bt switch --local searched for org and projects before checking it was allowed to create a local project
    Now the network call happens after the local check

Try it with bt switch -l -o 'BT Staging' -p bt-coding-agent-insights on cedric/prune-profiles VS on cedric/switch-local-asked-nonexistant-before-network-call, in a git repo without a .bt folder in it (usually in the git root).

Based on cedric/prune-profiles from #274, will be merged after it.
For reviews, don't forget to compare against cedric/prune-profiles and not against main.

first draft

BREAKING-CHANGE: --profile and --prefer-profile removed
Breaks any script using them
…n to use the new auth storage format orgid,email
The field is needed by OAuth but it's unused both bt and the backend
Therefore exposing it is useless
Now bt_cli is hardcoded as its value
 - Preserves separate OAuth and API-key login identities.
 - Keeps multiple API keys for the same org distinct using key hints.
 - Implements the intended precedence:
     1. Explicit --api-key
     2. --prefer-api-key
     3. OAuth
     4. BRAINTRUST_API_KEY
     5. Stored API key
 - Validates explicit/environment API keys against the requested org.
 - Does not fall back to OAuth when a selected key is invalid or belongs to another org.
 - Rejects API-key authentication in cross-org mode.
 - Pins the exact API-key login selected by bt switch or bt init.
 - Adds bt auth login --global/--local.
 - Adds filtering to bt auth logins --org/--prefer-api-key.
 - Changes bare bt auth logout to select from all saved logins instead of deleting the currently active one.
 - Adds bt auth logout --oauth and retains --api-key-hint.

 Config handling — src/config/mod.rs

 - Makes global/local merging org-safe:
     - A project is never inherited from another org.
     - project and project_id remain coupled.
     - Local project-without-org does not inherit the global org.

 - Stores cross-org as:

   ```json
     { "org": "" }
   ```

 - Ignores the legacy profile field.

 - Preserves unknown config keys during updates.

 - Only treats .bt/config.json as a local config; a bare .bt directory is not one.

 - Adds separate filesystem discovery rules for bt init.

 bt switch — src/switch.rs

 - Starts with a saved-login picker:
     - OAuth entries collapse into org choices.
     - API keys remain separate and display their hints.
     - Cross-org OAuth is selectable.
 - Automatically selects a sole login/project.
 - Prompts for project when multiple projects exist.
 - Pins a selected API-key slot exactly.
 - Implements global/local scope rules:
     - --global does not search for local config.
     - --local requires an existing .bt/config.json.
     - Interactive ambiguity opens a scope picker.
     - Non-interactive ambiguity errors before network work.
 - Preserves unknown config fields.
 - Fixes the scope-picker ANSI corruption you reported by passing plain labels to Dialoguer.

 bt init — src/init.rs

 - Adds:
     - --here
     - -f/--force

 - Searches upward for .bt, .git, home, or filesystem root using the specified boundary rules.

 - Resolves destination errors before authentication.

 - Uses the same saved-login/project selection behavior as switch.

 - Excludes cross-org from the picker because init requires a project.

 - Writes org, project, and project_id.

 - Reports permission/write failures with the affected path.

 - Now exposes the real destination error instead of only saying:

   ```text
     could not resolve `bt init` destination
   ```

 Cross-org CLI/status — src/args.rs, src/main.rs, src/status.rs

 - Normalizes these to canonical cross-org:

   ```sh
     --org cross-org
     --org ""
   ```

 - Displays cross-org as cross-org in human and JSON status output.

 - Prevents stale projects from being combined with cross-org context.

 - Makes --prefer-api-key fail actionably from cross-org context.
before it was always the same name which could lead to corruption if multiple bt used it at the same time
`bt datasets snapshots create my-dataset` would use the name of the OAuth login when the credentials used were BRAINTRUST_API_KEY, ie not OAuth
Always show current auth in bt status even if it's from API key in env
`bt switch --local` searched for org and projects before checking it was allowed to create a local project
Now the network call happens after the local check
@github-actions

Copy link
Copy Markdown
Contributor

Latest downloadable build artifacts for this PR commit 620defad1fc1:

Available artifact names
  • artifacts-build-global
  • artifacts-build-local-aarch64-pc-windows-msvc
  • artifacts-build-local-x86_64-pc-windows-msvc
  • artifacts-build-local-x86_64-apple-darwin
  • artifacts-build-local-aarch64-apple-darwin
  • artifacts-build-local-x86_64-unknown-linux-musl
  • artifacts-build-local-x86_64-unknown-linux-gnu
  • artifacts-build-local-aarch64-unknown-linux-gnu
  • artifacts-plan-dist-manifest
  • cargo-dist-cache

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant