Skip to content

v0.2.1 — --login-body-template + better hints

Choose a tag to compare

@shhac shhac released this 24 Apr 01:51
· 92 commits to main since this release
6f34972

Non-breaking additive release. Driven by feedback from a real LLM
smoke-test run against a staging API.

New: --login-body-template

Form auth's default flat-{username,password} body doesn't fit every
login API. Two cases this unlocks:

  • GraphQL-mutation logins (signin is a mutation POSTed to the regular
    /graphql endpoint, credentials nested in a JSON query+variables
    envelope).
  • OAuth2 password-grant bodies needing extra fields (grant_type,
    client_id, …) alongside the user credentials.
profile add myapi --type form \
  --login-url https://api.example.com/graphql \
  --username alice --password 'pw' \
  --login-body-template '{"query":"mutation($u:String!,$p:String!){
      signIn(input:{username:$u,password:$p}){ tokens { bearer }}}",
      "variables":{"u":"{{username}}","p":"{{password}}"}}' \
  --token-path data.signIn.tokens.bearer \
  --domain api.example.com

Placeholders: {{username}}, {{password}}, {{<extra-field-name>}}.
Values are JSON-string-escaped so credentials with quotes or
backslashes don't break the output. An unknown placeholder fails
loudly with fixable_by:human (typos can't silently break logins).
Content-Type is forced application/json when the template is set.

Hint improvements (feedback-driven)

  • Redirect-refused + allowlist-miss hints now include the exact
    profile allow <name> <host> <primary-secret-flags> command, per
    auth type. No more "widen --domain" and guessing which flag.
  • graphql llm-help gains an introspection example
    ({ __schema { queryType { fields { name } } } }) — the natural
    first move against an unfamiliar GraphQL API.

Install

brew install shhac/tap/agent-deepweb           # new
brew upgrade shhac/tap/agent-deepweb           # existing