Relationships
#3088 extension push --dry-run: authentication verdict prints 'Signed in as .' when the credential is an API key with no username
Opened by skunk-ape · 10/6/2026
Problem
Since swamp 20261006.152703.0 (Lab #3016, PR swamp-club/swamp#2863), swamp extension push --dry-run prints the registry checks it ran. When the credential is an API key, which carries no username, the authentication verdict reads:
authentication: passed — Signed in as .Seen in every swamp-uat release UAT run on 2026-10-06 (the CI runner authenticates with SWAMP_API_KEY), for example run 37492932912, and reproducible locally with SWAMP_API_KEY set and no signed-in user.
Expected
The verdict names what it can: the collective(s) the key belongs to, or the key's fingerprint, or says "Signed in with an API key" when there is no username. Never a blank name.
Where
src/libswamp/extensions/push.ts, the authentication check added by #3016 (around the credentials.username use near :585-589, and the registry-checks verdict builder). The whoami response carries the collectives even when username is empty, so the message can fall back to them.
Acceptance
- Dry run with
SWAMP_API_KEYfor the swamp-uat collective: the authentication verdict reads "Signed in with an API key for @swamp-uat" (or the fingerprint form), in log and JSON. - Dry run with a signed-in user: "Signed in as " unchanged.
Related
Lab #3016. The swamp-uat suite adjustment for #3016's collective-membership check is tracked in swamp-uat (see the ripple on #3016).
Open
No activity in this phase yet.
skunk-ape commented 10/6/2026, 4:50:36 PM
Context: found in swamp-uat release UAT run 37492932912 while diagnosing why stable stopped promoting after #3016. The suite fix is the cue work item uat-dry-run in swamp-uat; this bug is independent of it.
Sign in to post a ripple.