Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
22 commits
Select commit Hold shift + click to select a range
c13b864
Revert "chore: defer unreleased features to develop"
ratovarius Sep 11, 2026
c0fbd77
Merge remote-tracking branch 'origin/main' into chore/restore-develop…
ratovarius Sep 11, 2026
bab6c93
Merge pull request #17 from ratovarius/chore/restore-develop-features
ratovarius Sep 11, 2026
e6ef7a9
feat(docs): add suggestion workflow helper
ratovarius Sep 18, 2026
4716d5d
style: format docs suggestion helper
ratovarius Sep 18, 2026
5754258
style: apply rustfmt to docs helper tests
ratovarius Sep 18, 2026
b0c6482
feat(docs): read comments and referenced text
ratovarius Sep 18, 2026
f81bf9f
feat(docs): add comment creation helper
ratovarius Sep 18, 2026
9ea63db
fix(docs): harden suggested replacements
ratovarius Sep 18, 2026
16d8357
fix(docs): harden suggested replacements
ratovarius Sep 18, 2026
92ff044
fix(docs): address comment review findings
ratovarius Sep 18, 2026
19a9155
fix(docs): handle nested suggestion replacements
ratovarius Sep 18, 2026
b2d1787
fix(docs): handle nested suggestion replacements
ratovarius Sep 18, 2026
f941a79
fix(docs): preserve comment anchor segments
ratovarius Sep 18, 2026
c0ffd66
Merge pull request #18 from ratovarius/feat/docs-suggest-workflow
ratovarius Sep 18, 2026
ee47d51
Merge pull request #19 from ratovarius/feat/docs-read-comments
ratovarius Sep 18, 2026
6e3c58e
chore(release): prepare fork v0.23.0
ratovarius Sep 18, 2026
2d65de1
fix(release): repair pnpm metadata and file-root coverage
ratovarius Sep 18, 2026
484249b
Merge pull request #21 from ratovarius/chore/release-0.23.0
ratovarius Sep 18, 2026
a4544ee
fix(release): preserve credential and comment context
ratovarius Sep 18, 2026
33ebe36
fix(release): close PR 22 review findings
ratovarius Sep 18, 2026
1fc496b
Merge pull request #22 from ratovarius/fix/release-review
ratovarius Sep 18, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 0 additions & 5 deletions .changeset/current-clippy-baseline.md

This file was deleted.

7 changes: 0 additions & 7 deletions .changeset/develop-release-flow.md

This file was deleted.

7 changes: 0 additions & 7 deletions .changeset/maintained-public-fork.md

This file was deleted.

5 changes: 5 additions & 0 deletions .changeset/release-review-fixes.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"@googleworkspace/cli": patch
---

Harden credential fallback and preserve document tab context when resolving comment anchors.
6 changes: 0 additions & 6 deletions .changeset/rename-personal-fork.md

This file was deleted.

5 changes: 0 additions & 5 deletions .changeset/sheets-append-range.md

This file was deleted.

6 changes: 0 additions & 6 deletions .changeset/single-upstream-pilot.md

This file was deleted.

2 changes: 2 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -129,6 +129,7 @@ When adding new helpers or CLI flags that accept file paths, **always validate**
| -------------------------------------- | ---------------------------------------- | -------------------------------------------------------------------- |
| File path for writing (`--output-dir`) | `validate::validate_safe_output_dir()` | Absolute paths, `../` traversal, symlinks outside CWD, control chars |
| File path for reading (`--dir`) | `validate::validate_safe_dir_path()` | Absolute paths, `../` traversal, symlinks outside CWD, control chars |
| File path (`--output`, `--upload`) | `validate::validate_safe_file_path()` | Paths outside CWD or the trusted `GOOGLE_WORKSPACE_CLI_FILE_ROOT`, control chars, symlink escapes; `..` components with an explicit root |
| Enum/allowlist values (`--msg-format`) | clap `value_parser` (see `gmail/mod.rs`) | Any value not in the allowlist |

```rust
Expand Down Expand Up @@ -225,6 +226,7 @@ See [`src/helpers/README.md`](crates/google-workspace-cli/src/helpers/README.md)
| Variable | Description |
|---|---|
| `GOOGLE_WORKSPACE_CLI_CONFIG_DIR` | Override the config directory (default: `~/.config/gws`) |
| `GOOGLE_WORKSPACE_CLI_FILE_ROOT` | Trusted boundary for `--output` / `--upload` files (default: CWD). Must be an existing directory; canonicalized. Relative CLI paths remain CWD-relative. Does not expand directory validators. |

### OAuth Client

Expand Down
70 changes: 70 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,75 @@
# @googleworkspace/cli

## 0.23.0

### Minor Changes

- c13b864: Add `--allow-unknown-fields` to raw API methods with JSON request bodies. Explicitly
allow fields absent from Discovery recursively, including in dry runs, while
preserving validation of known fields, required fields, JSON, URLs and file paths.
Handwritten helpers retain strict validation.
- f81bf9f: Add `gws docs +comment create` for creating anchored Google Docs comments
without manually using preview-only request fields.
- b0c6482: Add `--include-comments` to `gws docs +read` to return comment threads and the
text referenced by each comment anchor range.
- c13b864: Add a standalone Python companion for visual Google Docs review bundles with
native exports, safe DOCX raster extraction, local HTML, optional PDF page
previews with explicitly unverified page coverage, revision observations,
and an offline fixture workflow. Preserve nested image occurrences and
legitimate asset reuse, and keep oversized optional comments from failing
the required bundle. Verify each export's exact canonical destination against
the real CLI receipt.
- c13b864: Add a standalone Python Docs review example that plans one literal text replacement,
binds it to a source revision and tab, applies it through existing gws commands,
and verifies the result without retrying ambiguous writes. Validate structures
and text ranges across all tabs before normalization, and preserve attempted or
confirmed mutation outcomes through final output failures and interruptions.
- c13b864: Add `gws docs +read` to translate documents into compact structured content with
recursive tabs, headings and an outline, styled text, suggestions, nested tables,
figure metadata, and reference markers. Preserve API indices and revisions,
reject partial field masks, and support the existing formatters, sanitization,
and credential-free dry-run.
- e6ef7a9: Add `gws docs +suggest` for creating and managing Google Docs suggestions,
including suggested insertions, exact replacements, range deletions, and
accept, reject, or delete actions.
- c13b864: Allow operators to set `GOOGLE_WORKSPACE_CLI_FILE_ROOT` to an existing directory
for `--output` and `--upload` paths while keeping CWD confinement by default.
Relative CLI paths remain CWD-relative. Reject invalid roots, parent traversal
with an explicit root, control characters, and symlink escapes, including
dangling symlinks. Directory flags retain their existing boundaries.

Reject canonical file paths that cannot be represented as UTF-8 at the CLI
string boundary, so explicit output/upload paths cannot silently become omitted
arguments.

- a3768d0: Add `--range` flag to `sheets +append` for targeting specific sheet tabs

### Patch Changes

- 5db4424: Keep Apps Script file selection compatible with the current Clippy checks.
- 05836b4: Keep unreleased work on develop. Require a versioned develop-to-main release PR,
run Rust and companion checks before publication, and create a fork-prefixed
GitHub release at the tested merge commit.
- 18410e9: Publish the integrated Docs workflow improvements in the independent ratovarius
fork with upstream attribution, source-install instructions, contribution
tracking, and credential-independent CI.
- c13b864: Skip authentication for Discovery-generated API and `docs +write` dry-runs.
Validate and preview requests without accessing the keyring or reading, changing,
or deleting stored credentials and token caches. Dry-runs work offline with a
fresh cached Discovery schema; schema fetching on first use or cache expiry is
unchanged. Real requests retain their existing authentication and error handling.
- c13b864: Preserve saved encrypted credentials and token caches when credential loading,
decryption, or keyring access fails. Report recovery guidance and stop authentication
instead of silently selecting plaintext credentials or another account through ADC.
Explicit token and credentials-file overrides and intentional logout remain unchanged.
- 05fb6c2: Rename the maintained fork to ratovarius/googleworkspace-cli and update repository
links, source installation examples, package metadata, CLI help, and agent guidance.
- 465b98f: Document credential preservation as the sole upstream pilot and keep further
development of the other improvements in this public fork.
- c13b864: Fix YAML mapping values containing empty arrays or objects by separating their
inline collection syntax from the mapping colon. This also fixes structured
Docs reader output with empty outlines, child tabs, or style maps.

## 0.22.5

### Patch Changes
Expand Down
Loading
Loading