You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
feat: default coder.useKeyring to true and harden shared credential handling (#1107)
Session tokens now also go to the OS keyring through the Coder CLI on macOS and Windows, so the terminal `coder` shares the extension's session. The extension's own secret storage is unchanged. Sharing the CLI's store made sign-out, missing-binary, and redirect handling explicit, and the CLI store model is now a single `CliAuth` type that every CLI call derives its flags from.
- Default `coder.useKeyring` to `true`; Linux and CLIs below 2.29 keep using a file. Pass `--use-keyring` explicitly and honor `CODER_CONFIG_DIR`.
- Ask at logout whether to sign the CLI out too when it holds the same token; leave a CLI signed in with another token alone, and always log the extension's own store out to revoke the token.
- Ask before adopting the CLI's session for a different user.
- Skip CLI credential steps with one info line when the binary is not downloaded yet; connect stores the token.
- Pass `--allow-redirects` to CLI 2.38+ so redirected deployment URLs keep working; require CLI 2.32 for CLI token reads.
- Cache `coder version` per binary and skip CLI reads when settings rule out the CLI's own store; run the logout check under cancellable progress.
- Show the CLI's error with Open Settings when storing fails, and Show Output when logout cannot remove every credential.
- Telemetry: `cli_token` replaces `keyring_token`; credential spans carry `store` and `outcome`; `auth.logout` gains `user_dismissed`.
Closes#1106
Copy file name to clipboardExpand all lines: package.json
+3-3Lines changed: 3 additions & 3 deletions
Original file line number
Diff line number
Diff line change
@@ -195,7 +195,7 @@
195
195
"ignoreSync": true
196
196
},
197
197
"coder.globalFlags": {
198
-
"markdownDescription": "Global flags to pass to every Coder CLI invocation. Enter each flag as a separate array item, in order. Do **not** include the `coder` command itself. See the [CLI reference](https://coder.com/docs/reference/cli) for available global flags.\n\nSupports `${env:VAR}`, `${userHome}`, and a leading `~`. For `--flag=value` items the expansion applies to the value half, so `--cfg=~/coder` works.\n\nSet `--global-config` here to point the CLI at a shared config directory (e.g. `--global-config=~/.config/coderv2` to share login/auth with the Coder CLI); requires a deployment on 2.31.0+ and is ignored when `#coder.useKeyring#` is active. The `--use-keyring` flag is ignored; use `#coder.useKeyring#` instead.\n\nFor `--header-command`, precedence is: `#coder.headerCommand#` setting, then `CODER_HEADER_COMMAND` environment variable, then the value specified here.",
198
+
"markdownDescription": "Global flags to pass to every Coder CLI invocation. Enter each flag as a separate array item, in order. Do **not** include the `coder` command itself. See the [CLI reference](https://coder.com/docs/reference/cli) for available global flags.\n\nSupports `${env:VAR}`, `${userHome}`, and a leading `~`. For `--flag=value` items the expansion applies to the value half, so `--cfg=~/coder` works.\n\nTo share a config directory with the `coder` CLI, add `--global-config` here (for example `--global-config=~/.config/coderv2`) or set `CODER_CONFIG_DIR`. Requires Coder CLI 2.32.0 or later. A `--use-keyring` item is ignored; use `#coder.useKeyring#` instead.\n\nFor `--header-command`, precedence is: `#coder.headerCommand#` setting, then `CODER_HEADER_COMMAND` environment variable, then the value specified here.",
199
199
"type": "array",
200
200
"items": {
201
201
"type": "string"
@@ -204,9 +204,9 @@
204
204
"ignoreSync": true
205
205
},
206
206
"coder.useKeyring": {
207
-
"markdownDescription": "Store session tokens in the OS keyring (macOS Keychain, Windows Credential Manager) instead of plaintext files. Requires CLI >= 2.29.0 (>= 2.31.0 to sync login from CLI to VS Code). This will attempt to sync between the CLI and VS Code since they share the same keyring entry. It will log you out of the CLI if you log out of the IDE, and vice versa. Has no effect on Linux.",
207
+
"markdownDescription": "Store session tokens in the OS keyring (macOS Keychain, Windows Credential Manager) instead of a file. Requires Coder CLI 2.29.0 or later; 2.32.0 or later to sign in with the CLI's existing session. Has no effect on Linux.\n\nThe keyring entry is shared with the `coder` CLI: signing in here also signs in the CLI, and signing out asks whether to sign out the CLI too.",
detail: `This will remove credentials for: ${selected.hostnames.join(", ")}\n\nYou'll need to log in again to access them.`,
857
+
detail: `This will remove credentials for: ${selected.hostnames.join(", ")}\n\nYou'll need to log in again to access them.${isKeyringEnabled(vscode.workspace.getConfiguration()) ? " This also signs the Coder CLI out where it shares a session." : ""}`,
0 commit comments