v0.10.4
Narrative --log UX for bootstrap + fetch
The previous --log output was structured JSONL designed for machine
consumers. This release rewrites the TTY path to tell the AAuth story
end-to-end:
bootstrap --ps <url> --log prints a TL;DR (what is AAuth, the four
protocol parties, the per-call flow, key properties) followed by a numbered
"one-time setup" card showing the agent identity + PS metadata exchange.
Writes a marker file so fetch --log knows the TL;DR was just shown.
fetch <url> --log in a TTY renders a 7- or 9-step story:
- AGENT signs request and calls resource (decoded agent_token visible in the Signature-Key header)
- RESOURCE returns 401 with a resource_token capability
- AGENT discovers PS, exchanges resource_token
- PS either deferred (202 + consent flow) or grants directly (warm path)
- USER approves consent in the browser if required
- AGENT retries with auth_token; resource returns data
Each step is one card with an actor-prefixed title (AGENT → RESOURCE, etc.),
the on-the-wire HTTP headers (Signature-Input, Signature, Signature-Key),
decoded JWT payloads with noise fields filtered, and inline annotations
("← same key as Step 1") anchoring the trust chain.
When fetch runs standalone (no recent bootstrap), the full TL;DR + an
"Already set up" block (agent identity recap) print at the top. When fetch
runs right after bootstrap, only a condensed 4-line flow diagram prints.
ANSI colors render only in a TTY and respect NO_COLOR. AAUTH_FORCE_PRETTY=1
forces pretty output for testing.
Piped output (NDJSON) is unchanged — programmatic consumers are not
affected.
TL;DR copy now aligns with the AAuth spec README: identity-first framing,
spec-correct protocol parties (agent / resource / PS / AS), and the
distinctive "no pre-registration, proof-of-possession, PS-centric consent"
properties.