fix: 营销 Skill 复用 CLI 登录态,无需用户提供 token - #29
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
营销 Skill 原先只读取 XYQ_ACCESS_KEY,已完成 CLI 网页登录的用户仍被要求另配密钥。现在上传、生成、查询和积分调用统一交给原生 marketing 命令,复用现有 AuthManager;未登录或凭据过期时引导 pippit-tool-cli login,不要求用户复制 access_token 或 Access Key。
Node 脚本保留离线预览、响应校验、状态 6/9 的交互处理、有界轮询和无鉴权媒体下载。生成请求通过 stdin 传入原生 CLI;凭据不返回给脚本,不进入参数或请求 JSON。显式环境覆盖继续遵守 CLI 原有优先级,不能静默切换身份。营销 API 禁止重定向及自动重提。
验证:
团队版边界:复用 CLI 现有身份范围,不改变鉴权语义;公开营销 API 没有 TeamID/团队切换参数,不注入团队字段或跨账号复用资源。Skill 与支持 marketing 命令的新 CLI 需一起发布;旧版本只提示升级,不回退到索要密钥。
发布:package.json 与 package-lock.json 已同步到 1.0.32,v1.0.32 tag 已推送,指向 58f0e21。由现有 Release 流水线构建并发布;版本检查、安装向导测试及 MR preflight 通过。