Skip to content

v0.10.4

Choose a tag to compare

@rohanharikr rohanharikr released this 13 May 12:21
· 71 commits to main since this release

Narrative --log UX for bootstrap + fetch

The previous --log output was structured JSONL designed for machine
consumers. This release rewrites the TTY path to tell the AAuth story
end-to-end:

bootstrap --ps <url> --log prints a TL;DR (what is AAuth, the four
protocol parties, the per-call flow, key properties) followed by a numbered
"one-time setup" card showing the agent identity + PS metadata exchange.
Writes a marker file so fetch --log knows the TL;DR was just shown.

fetch <url> --log in a TTY renders a 7- or 9-step story:

  • AGENT signs request and calls resource (decoded agent_token visible in the Signature-Key header)
  • RESOURCE returns 401 with a resource_token capability
  • AGENT discovers PS, exchanges resource_token
  • PS either deferred (202 + consent flow) or grants directly (warm path)
  • USER approves consent in the browser if required
  • AGENT retries with auth_token; resource returns data

Each step is one card with an actor-prefixed title (AGENT → RESOURCE, etc.),
the on-the-wire HTTP headers (Signature-Input, Signature, Signature-Key),
decoded JWT payloads with noise fields filtered, and inline annotations
("← same key as Step 1") anchoring the trust chain.

When fetch runs standalone (no recent bootstrap), the full TL;DR + an
"Already set up" block (agent identity recap) print at the top. When fetch
runs right after bootstrap, only a condensed 4-line flow diagram prints.

ANSI colors render only in a TTY and respect NO_COLOR. AAUTH_FORCE_PRETTY=1
forces pretty output for testing.

Piped output (NDJSON) is unchanged — programmatic consumers are not
affected.

TL;DR copy now aligns with the AAuth spec README: identity-first framing,
spec-correct protocol parties (agent / resource / PS / AS), and the
distinctive "no pre-registration, proof-of-possession, PS-centric consent"
properties.