Conversation
added 2 commits
September 4, 2026 16:55
…ult/sessions - ceki_sdk/_vault.py: ClientVault HTTP CRUD (list/get/create/update/delete), BrowserVault.save (profile.export → vault envelope) and restore (session.configure profile+fingerprint), cookie sanitization to the settable CDP subset, flat-profile → per-origin envelope normalization. - Client.rent(vault=...) restores the vault profile before applying fingerprint/masking; the browser is bound to the vault session id so a later browser.vault.save() overwrites it (PUT). - Browser.vault surface wired in __init__; CLI rent --vault SESSION_ID (one-shot + daemon path) and README vault section + example script. - tests/test_vault.py: 18 unit tests (mocked httpx + mocked relay); live dev-API roundtrip verified separately.
Task 11622 (Vault 7). Adds the `ceki vault` subcommand surface on top of ClientVault/BrowserVault from Vault 6 (SDK): - vault list [--json] [--per-page N] - vault get ID [--json] [-o FILE] (decrypted profile) - vault save FILE [--id ID] [--label L] - vault save --session SID [--id ID] [--no-session-storage] (live snapshot) - vault apply ID --session SID | --schedule N - vault delete ID Vault commands run over plain HTTP (no relay session), using the same Client/api_url + basic-auth overrides as connect(). Also fixes `ceki rent --vault` not forwarding the vault id through daemon IPC. Tests: tests/test_cli_vault.py (parser + mocked handler coverage).
Co-Authored-By: Claude Code <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Vault 6: Python SDK — работа с vault
Адаптация Python SDK под vault (спека Vault 1-5, бэкенд
/api/vault/sessions).Что сделано
Новый модуль
ceki_sdk/_vault.py:ClientVault— HTTP CRUD:list(),get(id)(decrypted profile),create(data, label),update(id, data),delete(id).BrowserVault— два сахарных слоя на живом браузере:browser.vault.save(label=...)—profile.export()→ нормализация в per-origin envelope → POST/PUT в vault (PUT, если сессия привязана к rent).browser.vault.restore(id | envelope)— GET vault →session.configure(profile=...): куки сразу, localStorage/sessionStorage буферизуются расширением и флашатся при первой навигации до origin; fingerprint уходит отдельным полем configure.sanitize_cookies— вычёркивает CDP-only поля (priority/size/sourcePort/...), которые браузер не принимает вNetwork.setCookies.normalize_profile_for_vault/minimal_vault_profile— конвертация плоскогоprofile.export()в envelope и обратно к extension-контракту.Интеграция:
Client.rent(..., vault=id | envelope)— restore профиля прямо при аренде (до fingerprint/masking); браузер биндится на vault-сессию (_vault_session_id).ceki rent --vault SESSION_ID(CLI, один shot + daemon path).examples/vault_roundtrip.py.Тесты:
tests/test_vault.py— 18 unit-тестов (mocked httpx + mocked relay WS). Live-раунд-трип против dev-API (list/get/create/update/delete) проверен вручную.Примечания
Authorization: Bearer <api_key>— для vault-операций нужен user-token.dev— MR создан вmaster(каноничный target для этого репо, как и все прошлые релизы).fingerprintиз vault не кладётся внутрьprofileconfigure — применяется отдельнымfingerprint-полем (extension обрабатывает его своим путём, чтобы не было двойного применения).