v0.2.1 — --login-body-template + better hints
Non-breaking additive release. Driven by feedback from a real LLM
smoke-test run against a staging API.
New: --login-body-template
Form auth's default flat-{username,password} body doesn't fit every
login API. Two cases this unlocks:
- GraphQL-mutation logins (signin is a mutation POSTed to the regular
/graphql endpoint, credentials nested in a JSON query+variables
envelope). - OAuth2 password-grant bodies needing extra fields (grant_type,
client_id, …) alongside the user credentials.
profile add myapi --type form \
--login-url https://api.example.com/graphql \
--username alice --password 'pw' \
--login-body-template '{"query":"mutation($u:String!,$p:String!){
signIn(input:{username:$u,password:$p}){ tokens { bearer }}}",
"variables":{"u":"{{username}}","p":"{{password}}"}}' \
--token-path data.signIn.tokens.bearer \
--domain api.example.comPlaceholders: {{username}}, {{password}}, {{<extra-field-name>}}.
Values are JSON-string-escaped so credentials with quotes or
backslashes don't break the output. An unknown placeholder fails
loudly with fixable_by:human (typos can't silently break logins).
Content-Type is forced application/json when the template is set.
Hint improvements (feedback-driven)
- Redirect-refused + allowlist-miss hints now include the exact
profile allow <name> <host> <primary-secret-flags>command, per
auth type. No more "widen --domain" and guessing which flag. graphql llm-helpgains an introspection example
({ __schema { queryType { fields { name } } } }) — the natural
first move against an unfamiliar GraphQL API.
Install
brew install shhac/tap/agent-deepweb # new
brew upgrade shhac/tap/agent-deepweb # existing