Skip to content

Commit e2bb489

Browse files
committed
Say which app security check prompts --json shows and how to turn them off
With --json, check can ask which app configuration to scan, offer to scan without one and then ask for the app, not only offer the instructions. The help now says so, and points automation at --no-input: a choice the command would have asked for then becomes an error, and a --client-id that needs a login fails instead of opening the browser. --list-files no longer claims it never prompts: its --client-id lookup can require a login.
1 parent e312523 commit e2bb489

3 files changed

Lines changed: 15 additions & 4 deletions

File tree

‎packages/app/src/cli/commands/app/security/check.test.ts‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -231,4 +231,15 @@ describe('app security check command', () => {
231231
expect(SecurityCheck.description).toContain('AppSecurityCheckResult')
232232
expect(SecurityCheck.descriptionWithMarkdown).toContain("in the result's `instructions` field")
233233
})
234+
235+
test('documents that --json still prompts, that --no-input turns prompts off, and that --client-id can need a login', () => {
236+
expect(SecurityCheck.descriptionWithMarkdown).toContain('it can ask which app configuration to scan')
237+
expect(SecurityCheck.descriptionWithMarkdown).toContain('pick or create the app')
238+
expect(SecurityCheck.descriptionWithMarkdown).toContain('pass `--no-input` to turn every prompt off')
239+
expect(SecurityCheck.descriptionWithMarkdown).toContain(
240+
'A choice the command would have asked for then becomes an error',
241+
)
242+
expect(SecurityCheck.descriptionWithMarkdown).toContain('which can require you to log in')
243+
expect(SecurityCheck.descriptionWithMarkdown).not.toMatch(/never prompts/)
244+
})
234245
})

‎packages/app/src/cli/commands/app/security/check.ts‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,9 +20,9 @@ The check scans the app directory and each \`--include-dir\`. Git ignore rules a
2020
2121
Use \`--exclude\` to skip more paths. Each value is a glob that is matched against the path relative to the working directory, so a path above it starts with \`../\`, and a name at any depth needs \`**/\`, for example \`--exclude '**/generated'\`. Repeat the flag to add globs. An exclusion can't remove the selected app configuration file. Quote each value so your shell doesn't expand \`*\`. The coding-agent instructions this check offers repeat the globs. Other \`app security\` commands don't take \`--exclude\` or \`--no-git-ignore\`, so pass the same flags each time you run the check.
2222
23-
Use \`--list-files\` to check the scope before scanning: it prints the files the check would gather, one path per line and relative to the app directory (\`{"files": [...]}\` with \`--json\`), and then stops. It writes no results and never prompts. \`--client-id\` is still checked, but doesn't change the list.
23+
Use \`--list-files\` to check the scope before scanning: it prints the files the check would gather, one path per line and relative to the app directory (\`{"files": [...]}\` with \`--json\`), and then stops. It writes no results and shows no prompts. \`--client-id\` is still checked, which can require you to log in, but doesn't change the list.
2424
25-
In interactive terminals, the command offers to copy the coding-agent instructions, print them, or choose nothing; copying is the default. In CI and other non-interactive environments, instructions aren't offered unless you pass \`--yes\`, which prints them. With \`--json\`, the command prompts the same way, before it prints the result, and the instructions you choose or pass \`--yes\` for are in the result's \`instructions\` field instead of printed. You can also run \`shopify app security instructions\` to print, copy, or write them later.`
25+
In interactive terminals, the command offers to copy the coding-agent instructions, print them, or choose nothing; copying is the default. In CI and other non-interactive environments, instructions aren't offered unless you pass \`--yes\`, which prints them. With \`--json\`, the command prompts the same way before it prints the result: it can ask which app configuration to scan, offer to scan without one and then ask you to pick or create the app, and offer the instructions. The instructions you choose, or pass \`--yes\` for, are in the result's \`instructions\` field instead of printed. In automation, pass \`--no-input\` to turn every prompt off. A choice the command would have asked for then becomes an error, so pass \`--config\`, or \`--without-app-config --client-id <client-id>\`, instead; a \`--client-id\` that needs a login fails instead of opening the browser. You can also run \`shopify app security instructions\` to print, copy, or write them later.`
2626

2727
static get jsonOutputSchema() {
2828
return securityCheckJsonOutputSchema

0 commit comments

Comments
 (0)