feat: zero-dependency npm registry setup script
scripts/setup-npm-registry.mjs configures npm to pull @redsentech packages (e.g. @redsentech/lean-harness) from GitHub Packages: - Discovers a token: --token flag > env (NPM_REGISTRY_TOKEN/ GITHUB_TOKEN/GH_TOKEN) > `gh auth token` > interactive masked prompt (raw-mode stdin, no echo, no external deps). - Verifies the token against the GitHub API, reports the authenticated login, and warns if the OAuth scopes are missing read:packages/ write:packages. - Writes/updates only its own two lines in .npmrc (scope registry + auth token), preserving every other line; idempotent on rerun. - Never prints the full token (masked in all output). - --dry-run, --unset (clean removal), --local, --scope, --registry, --skip-verify, --npmrc <path> flags. - Confirms the result with `npm whoami --registry ...`. Verified live end-to-end: real GitHub PAT via `gh auth token` -> verified against api.github.com -> written to a scratch .npmrc -> `npm whoami` succeeded. Also confirmed the scope-warning is accurate: installing @redsentech/lean-harness with a token lacking read:packages correctly 403s, exactly as the script warns it will. Adds tests/setup-npm-registry.test.mjs (7 hermetic tests: dry-run, write+preserve, token never printed, idempotent rerun, --unset, custom scope/registry, clean failure with no token). Adds "setup-npm-registry" npm script. Documents the script in README (The `lh` CLI section) and docs/QUICKSTART.md (install + troubleshooting). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
+2
-1
@@ -31,7 +31,8 @@
|
||||
"validate": "node scripts/validate.mjs",
|
||||
"test": "node --test tests/*.test.mjs",
|
||||
"lh": "node src/cli.mjs",
|
||||
"onboard": "node scripts/onboard.mjs"
|
||||
"onboard": "node scripts/onboard.mjs",
|
||||
"setup-npm-registry": "node scripts/setup-npm-registry.mjs"
|
||||
},
|
||||
"dependencies": {
|
||||
"web-tree-sitter": "^0.25.10"
|
||||
|
||||
Reference in New Issue
Block a user