Skip to content

BUILD-320 Updates to BUILD CLI - #53

Merged
jsanmartin123 merged 4 commits into
mainfrom
BUILD-320
Sep 29, 2026
Merged

jsanmartin123 merged 4 commits into
mainfrom
BUILD-320

Conversation

@jsanmartin123

@jsanmartin123 jsanmartin123 commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

BUILD-320 ports the SMS opt-in and voice MFA options from the web signup flow (BUILD-316/317) into the band CLI's Build account registration.

  • band account register gains --sms-opt-in — maps to promotionalCommsAccepted on POST /registration. This is marketing/PFT-campaign consent, separate from MFA-delivery consent.
  • New: band account send-code — drives the previously browser-only "send verification code" step (POST /registration/code). Requires --delivery-channel sms|voice; this is the "Voice MFA option" from the ticket. The flag has no default and is required, since choosing sms is itself the customer's consent to receive that code by text (there is no separate consent field on the wire).
  • New: band account verify — drives the "verify code" step (POST /registration/code/verify), completing phone verification and kicking off account provisioning.
  • Docs updated (AGENTS.md, README.md) so the documented flow matches: phone verification is now CLI-drivable end to end; only setting a password (via the emailed registration link) still requires a human. The agent-facing example in AGENTS.md includes an explicit STOP instruction so an agent waits for a human-supplied code instead of submitting the placeholder value shown in the example. README.md's "Account registration" command-reference table also now lists all three commands.

Endpoints stay on the existing /v1/express/registration... paths (not the newer /v1/build/registrations path found in api-specs) — kept as-is to match what's actually deployed today rather than introduce an unrelated migration in this PR.

Local testability

Added the infrastructure to actually test these commands without hitting production:

  • cmdutil.RegistrationHost() — register/send-code/verify now honor BW_API_URL like every other client in the codebase (previously hardcoded), so they can be pointed at a local mock (e.g. a WireMock stub, or the express-registration-service Prism setup) for manual testing.
  • registrationClient seam — the three commands now go through a swappable cmdutil.ClientFunc var instead of constructing the HTTP client inline, matching the existing cmdutil.VoiceClient pattern used by cmd/call/cmd/recording.
  • testutil.FakeClient.Post — was a no-op before (fine for the GET-only commands it was built for, useless for these POST-only ones). Now marshals a PostResult into the response the same way Get already does, and records the path/body it was called with.
  • cmd/account/golden_test.go — three golden tests (register, send-code, verify) exercising the real Cobra command end to end against the fake client, asserting both the exact --plain stdout bytes and the outbound request body (e.g. --delivery-channel " Voice " normalizes to "VOICE" on the wire, --sms-opt-in sets promotionalCommsAccepted: true). These run wherever go test ./... already runs — no new CI wiring needed.

Self-review follow-up

Ran a self-review pass and fixed two issues before opening this up:

  • --delivery-channel was originally optional with a silent default of sms — an omitted flag would record MFA consent without the caller explicitly choosing it. Now required.
  • The AGENTS.md example didn't tell an agent to pause before calling verify with a real code.

A third issue flagged in that same pass — no BW_API_URL support — is now fixed above rather than deferred.

🤖 Generated with Claude Code

@bwappsec

bwappsec commented Sep 28, 2026 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues
✅ Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@jsanmartin123
jsanmartin123 marked this pull request as ready for review September 29, 2026 11:49
@jsanmartin123
jsanmartin123 requested review from a team as code owners September 29, 2026 11:49
@jsanmartin123
jsanmartin123 merged commit 4812029 into main Sep 29, 2026
8 checks passed
@jsanmartin123
jsanmartin123 deleted the BUILD-320 branch September 29, 2026 14:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants