Expand description
CLI session file — §5.3.
The session file caches the PDS session tokens the CLI obtains at
cairn login time. Each subsequent authed command asks the PDS
for a fresh service auth JWT (via getServiceAuth) using the
access token stored here; the CLI never mints service auth JWTs
itself. §5.3 is explicit that this file is a moderator
credential equivalent to the PDS app password; the on-disk
invariants below are designed to catch any drift from that
security posture.
On-disk invariants checked on every load:
- Mode exactly
0o600. Wider → reject. - File owned by the current effective UID. Mismatch → reject.
versionfield equalsSESSION_VERSION. Mismatch → reject.
Writes are atomic: tempfile in the same directory (created with
mode 0o600 via tempfile::NamedTempFile, which uses
O_CREAT | O_EXCL with the target permissions set at open-time on
Unix), fsync, rename(2) into place. Same-directory POSIX rename
is atomic — cairn report’s auto-refresh-then-persist flow
relies on this.
Structs§
- Session
File - Cached PDS session + Cairn server identity. Everything needed to mint a service auth JWT at the PDS and send the result to Cairn, minus the moderator’s actual signing key (which lives at the PDS).
Enums§
- Session
Error - Error taxonomy for session-file operations. Surfaces enough context to the CLI dispatcher to choose the right exit code (see criterion G) without leaking the session contents.
Constants§
- SESSION_
FILE_ ENV - Env-var override for the session file path. §5.3 names this as the scripted/CI escape hatch: pre-bake a session on a secure machine and point CI at it via secret management.
- SESSION_
VERSION - Current schema version written to disk. A load that finds a
different value refuses to proceed rather than trying to migrate —
a schema change warrants an explicit
cairn loginre-auth.
Functions§
- default_
path - Resolve the session path:
CAIRN_SESSION_FILEenv var first, otherwise<config_dir>/cairn/session.jsonper XDG. - delete
- Idempotent removal of the session file.
Ok(())regardless of whether the file existed —cairn logouttreats “already gone” as success.