BUILD-320 Updates to BUILD CLI - #53
Merged
Merged
Conversation
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
jsanmartin123
marked this pull request as ready for review
September 29, 2026 11:49
TroyArcher
approved these changes
Sep 29, 2026
noahg1
approved these changes
Sep 29, 2026
venkatsram
approved these changes
Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
BUILD-320 ports the SMS opt-in and voice MFA options from the web signup flow (BUILD-316/317) into the
bandCLI's Build account registration.band account registergains--sms-opt-in— maps topromotionalCommsAcceptedonPOST /registration. This is marketing/PFT-campaign consent, separate from MFA-delivery consent.band account send-code— drives the previously browser-only "send verification code" step (POST /registration/code). Requires--delivery-channel sms|voice; this is the "Voice MFA option" from the ticket. The flag has no default and is required, since choosingsmsis itself the customer's consent to receive that code by text (there is no separate consent field on the wire).band account verify— drives the "verify code" step (POST /registration/code/verify), completing phone verification and kicking off account provisioning.AGENTS.md,README.md) so the documented flow matches: phone verification is now CLI-drivable end to end; only setting a password (via the emailed registration link) still requires a human. The agent-facing example inAGENTS.mdincludes an explicitSTOPinstruction so an agent waits for a human-supplied code instead of submitting the placeholder value shown in the example.README.md's "Account registration" command-reference table also now lists all three commands.Endpoints stay on the existing
/v1/express/registration...paths (not the newer/v1/build/registrationspath found inapi-specs) — kept as-is to match what's actually deployed today rather than introduce an unrelated migration in this PR.Local testability
Added the infrastructure to actually test these commands without hitting production:
cmdutil.RegistrationHost()—register/send-code/verifynow honorBW_API_URLlike every other client in the codebase (previously hardcoded), so they can be pointed at a local mock (e.g. a WireMock stub, or theexpress-registration-servicePrism setup) for manual testing.registrationClientseam — the three commands now go through a swappablecmdutil.ClientFuncvar instead of constructing the HTTP client inline, matching the existingcmdutil.VoiceClientpattern used bycmd/call/cmd/recording.testutil.FakeClient.Post— was a no-op before (fine for the GET-only commands it was built for, useless for these POST-only ones). Now marshals aPostResultinto the response the same wayGetalready does, and records the path/body it was called with.cmd/account/golden_test.go— three golden tests (register,send-code,verify) exercising the real Cobra command end to end against the fake client, asserting both the exact--plainstdout bytes and the outbound request body (e.g.--delivery-channel " Voice "normalizes to"VOICE"on the wire,--sms-opt-insetspromotionalCommsAccepted: true). These run wherevergo test ./...already runs — no new CI wiring needed.Self-review follow-up
Ran a self-review pass and fixed two issues before opening this up:
--delivery-channelwas originally optional with a silent default ofsms— an omitted flag would record MFA consent without the caller explicitly choosing it. Now required.AGENTS.mdexample didn't tell an agent to pause before callingverifywith a real code.A third issue flagged in that same pass — no
BW_API_URLsupport — is now fixed above rather than deferred.🤖 Generated with Claude Code