Replace Ed25519 with hashed API tokens and an in-Firefox client manager.
This commit is contained in:
+19
-22
@@ -1,5 +1,5 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Call Firefox Agent Bridge with a registered Ed25519 client key."""
|
||||
"""Call Firefox Agent Bridge with a Bearer token from FAB_TOKEN or a file."""
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
@@ -11,21 +11,21 @@ import urllib.request
|
||||
from pathlib import Path
|
||||
from typing import Any
|
||||
|
||||
ROOT = Path(__file__).resolve().parents[1]
|
||||
sys.path.insert(0, str(ROOT))
|
||||
|
||||
from fab_auth import load_key_bundle, sign_headers # noqa: E402
|
||||
|
||||
DEFAULT_BASE = os.environ.get("FAB_URL", "http://127.0.0.1:17634")
|
||||
|
||||
|
||||
def key_path() -> Path:
|
||||
env = os.environ.get("FAB_KEY_FILE")
|
||||
def token_value(explicit: str | None = None) -> str:
|
||||
if explicit:
|
||||
return explicit.strip()
|
||||
env = os.environ.get("FAB_TOKEN")
|
||||
if env:
|
||||
return Path(env)
|
||||
return env.strip()
|
||||
path = os.environ.get("FAB_TOKEN_FILE")
|
||||
if path:
|
||||
return Path(path).expanduser().read_text(encoding="utf-8").strip()
|
||||
raise SystemExit(
|
||||
"no client key: set FAB_KEY_FILE or pass --key "
|
||||
"(python tools/register_client.py add --name NAME --write-key PATH)"
|
||||
"no token: set FAB_TOKEN, or FAB_TOKEN_FILE, or pass --token. "
|
||||
"Generate one from the add-on toolbar → Manage clients."
|
||||
)
|
||||
|
||||
|
||||
@@ -33,20 +33,17 @@ def call(
|
||||
method: str,
|
||||
args: list[Any] | None = None,
|
||||
base: str = DEFAULT_BASE,
|
||||
key_file: Path | None = None,
|
||||
token: str | None = None,
|
||||
) -> Any:
|
||||
payload = json.dumps({"method": method, "args": args or []}).encode("utf-8")
|
||||
path = "/v1/call"
|
||||
bundle = load_key_bundle(key_file or key_path())
|
||||
headers = {
|
||||
"Content-Type": "application/json",
|
||||
**sign_headers(bundle, "POST", path, payload),
|
||||
}
|
||||
req = urllib.request.Request(
|
||||
base.rstrip("/") + path,
|
||||
base.rstrip("/") + "/v1/call",
|
||||
data=payload,
|
||||
method="POST",
|
||||
headers=headers,
|
||||
headers={
|
||||
"Authorization": f"Bearer {token_value(token)}",
|
||||
"Content-Type": "application/json",
|
||||
},
|
||||
)
|
||||
try:
|
||||
with urllib.request.urlopen(req, timeout=20) as resp:
|
||||
@@ -69,12 +66,12 @@ def main() -> int:
|
||||
parser.add_argument("method", help="e.g. bookmarks.search or meta.methods")
|
||||
parser.add_argument("args_json", nargs="?", default="[]", help="JSON array of arguments")
|
||||
parser.add_argument("--url", default=DEFAULT_BASE)
|
||||
parser.add_argument("--key", type=Path, help="client key bundle (or FAB_KEY_FILE)")
|
||||
parser.add_argument("--token", help="override FAB_TOKEN")
|
||||
ns = parser.parse_args()
|
||||
args = json.loads(ns.args_json)
|
||||
if not isinstance(args, list):
|
||||
raise SystemExit("args_json must be a JSON array")
|
||||
print(json.dumps(call(ns.method, args, base=ns.url, key_file=ns.key), indent=2))
|
||||
print(json.dumps(call(ns.method, args, base=ns.url, token=ns.token), indent=2))
|
||||
return 0
|
||||
|
||||
|
||||
|
||||
@@ -37,6 +37,5 @@ Set-ItemProperty -Path $regPath -Name "(default)" -Value $ManifestPath
|
||||
Write-Host "registered $regPath"
|
||||
|
||||
Write-Host ""
|
||||
Write-Host "Register a client key for tooling (private key stays out of $StateDir):"
|
||||
Write-Host " python tools\register_client.py add --name cursor-agent --write-key `$HOME\.fab\cursor-agent.json"
|
||||
Write-Host "Then load the extension and set FAB_KEY_FILE to that path."
|
||||
Write-Host "Load the add-on, then use the toolbar icon → Manage clients to generate a secret."
|
||||
Write-Host "Put that fab_… token in FAB_TOKEN for scripts. Do not store it under $StateDir."
|
||||
|
||||
+15
-27
@@ -1,5 +1,5 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Register, list, or revoke Ed25519 clients for Firefox Agent Bridge."""
|
||||
"""CLI fallback for client secrets. Prefer the add-on Manage clients page."""
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
@@ -10,42 +10,30 @@ from pathlib import Path
|
||||
ROOT = Path(__file__).resolve().parents[1]
|
||||
sys.path.insert(0, str(ROOT))
|
||||
|
||||
from fab_auth import CLIENTS_PATH, load_clients, register_client, revoke_client # noqa: E402
|
||||
from fab_auth import CLIENTS_PATH, create_client, list_clients, revoke_client # noqa: E402
|
||||
|
||||
|
||||
def main() -> int:
|
||||
parser = argparse.ArgumentParser(description="Manage Firefox Agent Bridge clients")
|
||||
parser = argparse.ArgumentParser(description="Manage Firefox Agent Bridge clients (CLI)")
|
||||
sub = parser.add_subparsers(dest="cmd", required=True)
|
||||
|
||||
add = sub.add_parser("add", help="generate a keypair and register the public half")
|
||||
add.add_argument("--name", required=True, help="label, e.g. cursor-agent")
|
||||
add.add_argument(
|
||||
"--write-key",
|
||||
required=True,
|
||||
type=Path,
|
||||
help="private key bundle path for tooling (must not be under LocalAppData\\firefox-agent-bridge)",
|
||||
)
|
||||
|
||||
sub.add_parser("list", help="show registered public clients")
|
||||
|
||||
drop = sub.add_parser("revoke", help="drop a client by name or id")
|
||||
add = sub.add_parser("add", help="generate a secret (printed once)")
|
||||
add.add_argument("--name", required=True)
|
||||
sub.add_parser("list")
|
||||
drop = sub.add_parser("revoke")
|
||||
drop.add_argument("name_or_id")
|
||||
|
||||
ns = parser.parse_args()
|
||||
if ns.cmd == "add":
|
||||
info = register_client(ns.name, ns.write_key)
|
||||
print(json.dumps(info, indent=2))
|
||||
print(f"give {info['key_file']} to tooling via FAB_KEY_FILE or --key", file=sys.stderr)
|
||||
created = create_client(ns.name)
|
||||
print(created["token"])
|
||||
print(
|
||||
f"id={created['id']} name={created['name']} — store that token in FAB_TOKEN; it will not be shown again.",
|
||||
file=sys.stderr,
|
||||
)
|
||||
return 0
|
||||
if ns.cmd == "list":
|
||||
rows = [
|
||||
{"id": c.get("id"), "name": c.get("name"), "created": c.get("created")}
|
||||
for c in load_clients()
|
||||
]
|
||||
print(json.dumps({"store": str(CLIENTS_PATH), "clients": rows}, indent=2))
|
||||
print(json.dumps({"store": str(CLIENTS_PATH), "clients": list_clients()}, indent=2))
|
||||
return 0
|
||||
revoke_client(ns.name_or_id)
|
||||
print(json.dumps({"revoked": ns.name_or_id}))
|
||||
print(json.dumps({"revoked": revoke_client(ns.name_or_id)}))
|
||||
return 0
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user