Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 7 additions & 7 deletions src/commands/device.ts
Original file line number Diff line number Diff line change
Expand Up @@ -44,8 +44,7 @@ const SCHEDULED_TASK_NAME = "AetherDeviceRuntime";
interface EnrollResponse {
device_id?: string;
device_token?: string;
device_command_key?: string;
display_name?: string;
command_key_hex?: string;
}

function daemonScriptPath(): string {
Expand Down Expand Up @@ -202,23 +201,24 @@ async function enroll(ctx: AppContext, flags: CommandFlags): Promise<number> {
let resp: EnrollResponse;
try {
resp = await ctx.api.postJson<EnrollResponse>(DEVICE_ENROLL_PATH, {
display_name: hostname(),
client: "aether-cli",
client_label: hostname(),
allowed_projects: [],
});
} catch (err) {
process.stderr.write(`enrollment failed: ${err instanceof Error ? err.message : String(err)}\n`);
return DEVICE_EXIT.failed;
}
if (!resp.device_id || !resp.device_token || !resp.device_command_key) {
if (!resp.device_id || !resp.device_token ||
!resp.command_key_hex || !/^[0-9a-f]{64}$/i.test(resp.command_key_hex)) {
process.stderr.write("enrollment response was missing the device id, token, or command key.\n");
return DEVICE_EXIT.failed;
}
const record: EnrollmentRecord = {
device_id: resp.device_id,
device_token: resp.device_token,
device_command_key: resp.device_command_key,
device_command_key: resp.command_key_hex,
// Display metadata only — the hostname never authenticates the device.
display_name: resp.display_name ?? hostname(),
display_name: hostname(),
base_url: resolved.url,
enrolled_at: Date.now(),
};
Expand Down
22 changes: 14 additions & 8 deletions test/device_command.test.ts
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
import { test } from "node:test";
import assert from "node:assert/strict";
import { mkdirSync, mkdtempSync, rmSync, writeFileSync } from "node:fs";
import { tmpdir } from "node:os";
import { hostname, tmpdir } from "node:os";
import { join } from "node:path";
import { cmdDevice, DEVICE_EXIT, deviceHealthState, resolveEnrollBaseUrl } from "../src/commands/device.js";
import { findDispatchedCliCommand } from "../src/commands/cli_registry.js";
Expand Down Expand Up @@ -95,22 +95,28 @@ test("device last reports unenrolled without leaking secrets", async () => {

test("device enroll saves the enrollment record", async () => {
await withConfigDir(async () => {
let posted: unknown;
const ctx = fakeCtx({
api: {
postJson: async () => ({
postJson: async (path: string, body: unknown) => {
posted = { path, body };
return {
device_id: "dev-99",
device_token: "dtok",
device_command_key: "dkey",
display_name: "host",
}),
command_key_hex: "ab".repeat(32),
};
},
} as unknown as AppContext["api"],
});
const { code, out } = await capture(() => cmdDevice(ctx, ["enroll"], NOOP_FLAGS));
assert.equal(code, DEVICE_EXIT.ok);
assert.match(out, /dev-99/);
const record = loadEnrollment();
assert.equal(record?.device_id, "dev-99");
assert.equal(record?.device_command_key, "dkey");
assert.equal(record?.device_command_key, "ab".repeat(32));
assert.deepEqual(posted, { path: "/device/v1/enroll", body: {
client_label: hostname(), allowed_projects: [],
} });
});
});

Expand Down Expand Up @@ -177,7 +183,7 @@ test("device enroll --base-url persists the override into the enrollment record"
const ctx = fakeCtx({
cfg: { ...DEFAULT_CONFIG, baseUrl: "https://config.example.test" },
api: {
postJson: async () => ({ device_id: "dev-flag", device_token: "t", device_command_key: "k" }),
postJson: async () => ({ device_id: "dev-flag", device_token: "t", command_key_hex: "ab".repeat(32) }),
} as unknown as AppContext["api"],
});
const { code } = await capture(() =>
Expand All @@ -193,7 +199,7 @@ test("device enroll without --base-url still uses config, unchanged", async () =
const ctx = fakeCtx({
cfg: { ...DEFAULT_CONFIG, baseUrl: "https://config.example.test" },
api: {
postJson: async () => ({ device_id: "dev-cfg", device_token: "t", device_command_key: "k" }),
postJson: async () => ({ device_id: "dev-cfg", device_token: "t", command_key_hex: "ab".repeat(32) }),
} as unknown as AppContext["api"],
});
await capture(() => cmdDevice(ctx, ["enroll"], NOOP_FLAGS));
Expand Down
Loading