Conversation
- `auth issue-ably-token` / `issue-jwt-token` resolve the token's client ID through one helper: --client-id, else the client ID the CLI acts as. "*" is refused, and "none" still issues an anonymous token but warns that apps requiring identified clients reject it. - Token output always states the identity: `Client ID: anonymous` in human output and `clientId: null` in JSON, rather than omitting it. - `auth issue-jwt-token --client-type server` adds the signed `x-ably-clientType=server` claim, which is the only way a token-authenticated client can be classified as a server. - `auth revoke-token` goes through the SDK's `auth.revokeTokens` instead of a hand-rolled HTTPS call to a hardcoded rest.ably.io, so it honours the configured endpoint and reports per-target failures. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
WalkthroughThis PR hardens the three Changes
Review Notes
|
umair-ably
added this pull request to stack #465
October 1, 2026 14:14
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
auth issue-ably-token/issue-jwt-tokenresolve the token's clientID through one helper: --client-id, else the client ID the CLI acts
as. "*" is refused, and "none" still issues an anonymous token but
warns that apps requiring identified clients reject it.
Client ID: anonymousinhuman output and
clientId: nullin JSON, rather than omitting it.auth issue-jwt-token --client-type serveradds the signedx-ably-clientType=serverclaim, which is the only way atoken-authenticated client can be classified as a server.
auth revoke-tokengoes through the SDK'sauth.revokeTokensinsteadof a hand-rolled HTTPS call to a hardcoded rest.ably.io, so it honours
the configured endpoint and reports per-target failures.