cloud auth status accepts inherited --api-key and --api-secret flags but ignores them when reporting the active credential source. A user cannot use status to inspect the highest-precedence source they supplied.
Reproduced with installed CLI 0.5.0, main df81e46cfec0bb58ea981d17cc6fd2de24442e7d, in an isolated project/process with no saved, environment or OAuth credentials:
clickhousectl cloud auth status --api-key qa-placeholder-key --api-secret qa-placeholder-secret --json
Exit 0; all three returned rows (OAuth, API key, Env vars) say Not configured, with no active source. These are synthetic values and no network verification is required to reproduce. This does not show that ordinary API commands ignore explicit credentials.
Auth dispatch does not pass inherited credentials to the auth handler; status resolves active state without those arguments.
Expected behavior:
- Include explicit command-line credentials in source selection/status, consistently with documented precedence: flags, saved credentials, environment, OAuth.
- Report the source in both human and JSON output, keeping other configured sources distinguishable from the active one.
- Do not echo secrets or claim that a supplied key was verified by the server. Preserve ordinary command authentication behavior.
- Cover flags alone and flags outranking other sources with isolated behavior tests.
Related closed issues #109 and #336 addressed environment visibility; #125 addressed API-key identity. This is the explicit-flags omission, not a reopening of those broader requests. No release milestone or blocker designation is requested.
cloud auth statusaccepts inherited--api-keyand--api-secretflags but ignores them when reporting the active credential source. A user cannot use status to inspect the highest-precedence source they supplied.Reproduced with installed CLI 0.5.0, main
df81e46cfec0bb58ea981d17cc6fd2de24442e7d, in an isolated project/process with no saved, environment or OAuth credentials:Exit 0; all three returned rows (OAuth, API key, Env vars) say
Not configured, with no active source. These are synthetic values and no network verification is required to reproduce. This does not show that ordinary API commands ignore explicit credentials.Auth dispatch does not pass inherited credentials to the auth handler; status resolves active state without those arguments.
Expected behavior:
Related closed issues #109 and #336 addressed environment visibility; #125 addressed API-key identity. This is the explicit-flags omission, not a reopening of those broader requests. No release milestone or blocker designation is requested.