Repository navigation
feat(app): extend the live grant instead of replacing it - #87
Merged
Merged
Conversation
Login always printed "Credentials saved to ~/.vana/auth.json", even when VANA_HOME moved the file or a non-production Account gave it its own name (auth.account-dev.vana.org.json). It now prints getAuthFilePath(), home-shortened. Claude-Session: https://claude.ai/code/session_01Fcv6uEy4zcXaigzDNxeW3j
The gateway keeps one grant per owner and app, and an approval replaces its scopes. `vana app request` now reads the app's live grant when this machine already holds an approval for the app key (or with --owner) and asks for the union, printing what it keeps, adds and removes first. --remove-scopes gives entries up, --no-merge-grant sends --scopes verbatim. Two different earlier approvers are never guessed between. The --json outcome carries kept, added, removed and grantUnion. The merge is a local copy of the SDK's mergeWithLiveGrant (vana-sdk#215, unreleased); removeScopes reaches the approval page once the SDK pin is bumped to the release that sends it. Claude-Session: https://claude.ai/code/session_01Fcv6uEy4zcXaigzDNxeW3j
Bump @opendatalabs/vana-sdk to 4.3.1, which ships mergeWithLiveGrant and removeScopes on createAccessRequest. The local copy of the merge becomes a re-export plus the flag-worded conflict check, removeScopes goes on the request body as a typed field, and a malformed --remove-scopes entry is refused as bad usage before any call. Claude-Session: https://claude.ai/code/session_01Fcv6uEy4zcXaigzDNxeW3j
Since vana-sdk 4.2.0 the jobs client signs a quoted price on its own when the gateway answers 402. Pass maxPrice "0" so a charged enclave read stops before anything is signed and exits 4 as payment_required, as the CLI promised before the bump. Claude-Session: https://claude.ai/code/session_01Fcv6uEy4zcXaigzDNxeW3j
github-actions Bot
pushed a commit
that referenced
this pull request
Oct 8, 2026
## [0.40.0](v0.39.0...v0.40.0) (2026-10-08) ### Features * **app:** extend the live grant instead of replacing it ([#87](#87)) ([545af5c](545af5c)), closes [vana-sdk#215](vana-com/vana-sdk#215) ### Bug Fixes * **server:** run personal server 1.31.0 ([#88](#88)) ([34f8fe1](34f8fe1))
Contributor
|
🎉 This PR is included in version 0.40.0 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The gateway keeps one grant per (owner, app). An approval replaces that grant's scopes, so
vana app request --scopes whoop.recoveryfrom an app that already holdsoura.sleepwould leave it withwhoop.recoveryalone. Apps have been rebuilding the union by hand.What
vana app request:--scopes.--remove-scopes a,b: live entries to give up. Matched verbatim. A scope both requested and removed is exit 2.--owner <address>: whose grant to extend. Needed when two different people approved this app from this machine; the CLI never guesses between them (owner_ambiguous), because merging one person's scopes would ask the other for data they never granted.--no-merge-grant: send--scopesverbatim.--jsonoutcomes (approved, pending under--no-input, denied, timed out) carrykept,added,removedandgrantUnion(status:merged,no_live_grant,owner_unknown,owner_ambiguous,disabled,unavailable; plusowner,grantId,reason,notCarried).--scopesandstatus: "unavailable".notCarried.vana app askgoes through the same path.removeScopes, sovana app requests showchecks the replaced-grant state against what was actually asked.Also, from a separate report:
vana loginalways printed "Credentials saved to ~/.vana/auth.json". It now prints the real file (getAuthFilePath(), home-shortened), which followsVANA_HOMEand the Account environment (for exampleauth.account-dev.vana.org.json).SDK dependency
Bumps
@opendatalabs/vana-sdk4.0.0 to 4.3.1 (exact pin, which the SEA build carries through). The merge now comes from the SDK (mergeWithLiveGrant/unionGrantScopes);src/core/grant-union.tsis a re-export plus the conflict check worded for the CLI flags.removeScopesgoes on the DCR body as a typed field. A malformed--remove-scopesentry is exit 2 before any call.4.3.1 rather than 4.3.0: 4.2.0 and 4.3.0 shipped
dist/protocol/jobs-client.jswith an extensionless../config/contracts.configimport that Node's ESM loader cannot resolve (fixed in vana-sdk#216).Between 4.0.0 and 4.3.1 the jobs client started signing a quoted price on its own when the gateway answers 402. The enclave leg of
vana app readnow passesmaxPrice: "0", so a charged enclave read stops before anything is signed and exits 4 aspayment_requiredinstead of spending without--pay. The other SDK changes in that range (mainnet enclave trust anchors,JobTransportError.details) need nothing here.Tests
test/cli/app-request.test.ts: merge with removal, the printed plan, no earlier approval (no gateway call), two approvers (no gateway call),--owner,--no-merge-grant, gateway down, requested-and-removed conflict, question source not carried, bad--owner.test/cli/auth.test.ts: the saved-credentials line for production, dev Account, andVANA_HOME. All gateway and controller calls are fakes.test/cli/app-read-loop.test.ts: enclave read sendsmaxPrice: "0"and maps a refused quote to exit 4.pnpm validategreen (772 tests), run with tempHOMEandVANA_HOME.Release
featcommit, so semantic-release cuts 0.40.0. The default changes: a repeat request from the same app key now asks for the union instead of replacing.https://claude.ai/code/session_01Fcv6uEy4zcXaigzDNxeW3j