Conversation
browserCliLogin called term.GetState(os.Stdin.Fd()) unconditionally,
which returns ENOTSUP ("operation not supported by device") when stdin
is a pipe rather than a TTY. The CLI treated that as fatal, printed
"Login via browser failed", and fell back to the interactive email
prompt, which also failed because there was no stdin. Net effect: an
AI agent spawning `infisical login` as a subprocess could not complete
browser login at all.
Guard both term.GetState/restoreTerminal and the askToPasteJwtToken
paste-fallback goroutine behind an isatty check. Neither is useful in
non-TTY contexts, and the browser callback flow itself requires no
terminal. Interactive terminal behavior is unchanged.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Adds the five CLI verbs an AI-agent quickstart prompt needs to drive end to end without dashboard clicks, backed by the existing REST API: - `infisical init --yes --project-id <id>`: non-interactive .infisical.json write; skips the org/project pickers so an agent can link a directory once it already has a project id. - `infisical projects list [--json]` and `infisical projects create --name [--description] [--slug] [--json]`: wraps GET /v1/workspace and POST /v2/workspace with machine-readable output. Create returns id + name + slug + orgId + environments and defaults shouldCreateDefaultEnvs to true. - `infisical org list [--json]`: enumerates the user's org memberships so an agent can pick one before creating a project. - `infisical import [--path] [--env] [--yes] [--json] [--add-gitignore]`: discovers .env, .env.local, .env.development, .env.staging, and .env.production under --path; previews key names (never values); uploads via util.SetRawSecrets; checks .gitignore, and optionally appends missing entries; never deletes the source. The CLI owns the file parsing so the agent never has to open a .env itself. Adds packages/api/model.go request/response types for project creation and packages/api/api.go CallCreateProject. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Contributor
PR overviewAll previously flagged issues have been addressed. No open security concerns remain on this pull request. Security reviewNo open security issues remain on this pull request. Fixed/addressed: 1 · PR risk: 0/10 |
Contributor
|
This was referenced Sep 25, 2026
akhilmhdh
self-requested a review
September 25, 2026 17:10
varonix0
requested changes
Sep 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description 📣
Lets an AI agent (or a script) set up Infisical in a project without interactive prompts that fail when there's no terminal. This is part of the implementation of AI-agent quickstart flow from:
The agent runs these commands, and the user logs in or signs up in the browser.
New commands
infisical projects list/projects create --name <name>list and create projects in the current org.--jsonreturnsid,name, andorgId(plusslugandenvironmentson create).Updated commands
infisical loginno longer fails when run without a terminal. It skips saving the terminal state and the "paste your token" fallback, and waits for the browser as usual.infisical initgets--project-id <id>, which links a directory without the org and project pickers, and--force, which overwrites an existing.infisical.json. Without a terminal,initexits with a message pointing at--forceinstead of prompting.infisical org listgets--json, including which org iscurrent.Type ✨
Tests 🛠️
Tested against a local Infisical instance, including a full agent run: sign up in the browser, create and link a project, import
.env, theninfisical run.