use std::path::Path;
use super::error::CliError;
use super::operator_session::OperatorSession;
use super::pds::PdsClient;
pub async fn login(
pds_url: &str,
handle: &str,
app_password: &str,
session_path: &Path,
) -> Result<OperatorSession, CliError> {
let pds = PdsClient::new(pds_url)?;
let resp = pds.create_session(handle, app_password).await?;
let session = OperatorSession {
version: super::operator_session::OPERATOR_SESSION_VERSION,
pds_url: pds_url.to_string(),
operator_did: resp.did,
operator_handle: resp.handle,
access_jwt: resp.access_jwt,
refresh_jwt: resp.refresh_jwt,
};
session
.save(session_path)
.map_err(|e| CliError::Config(format!("writing operator session: {e}")))?;
Ok(session)
}
pub fn post_login_warning(session: &OperatorSession, path: &Path) -> String {
format!(
"Logged in as operator {did}.\n\
Session cached at {path}.\n\
\n\
WARNING: this session file authenticates as the LABELER's PDS\n\
account. Anyone with read access to this file can push records\n\
to {pds}, including overwriting the service record. Protect\n\
it like the app password itself — a stolen file lives until\n\
`cairn operator-logout` revokes it or the PDS session expires.",
did = session.operator_did,
path = path.display(),
pds = session.pds_url,
)
}