paperclip/cli/src/__tests__
Dotta 3da58b185e
fix(cli): restore test-drive credential inputs (#12898)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - The CLI provides a test-drive command for a ready local test
instance.
> - That command must accept a provider credential before it creates the
first agent.
> - The command did not accept a literal key and could lose an exported
key during server startup.
> - This pull request accepts both credential paths and captures the CLI
environment before startup.
> - The benefit is a reliable one-command test drive from an existing
shell.

## Linked Issues or Issue Description

Refs #12894

**What happened?**

`paperclipai test-drive --api-key <value>` failed because the option did
not exist. An exported canonical provider variable could also become
unavailable before the post-listen bootstrap read it.

**Expected behavior**

The command must accept a literal key when the operator requests it. The
command must also use a provider variable that was present when the CLI
started.

**Steps to reproduce**

1. Export `ANTHROPIC_API_KEY` in the shell.
2. Run `pnpm paperclipai test-drive`.
3. Observe that bootstrap can report that no credential exists.
4. Run `pnpm paperclipai test-drive --api-key test-value`.
5. Observe that Commander reports an unknown option on the prior
implementation.

**Paperclip version or commit**

The problem exists on `master` after #12894.

**Deployment mode**

Local development with `pnpm` and the embedded database.

## What Changed

- Add the `--api-key <value>` test-drive option.
- Keep `--api-key` and `--api-key-env` mutually exclusive.
- Capture provider variables before in-process server startup changes
the process environment.
- Redact literal and environment-backed credentials from Paperclip
errors, including custom environment-variable names with surrounding
whitespace.
- Scrub split and joined literal-key forms from the JavaScript
`process.argv` view before telemetry, diagnostics, API work, or server
startup.
- Warn about process argument and shell history exposure without
printing the key.
- Add tests for literal keys, option conflicts, environment snapshots,
argv handling, and error redaction.
- Update the CLI and development documentation, including the remaining
external argv exposure tradeoff.

## Verification

- `pnpm exec vitest run cli/src/__tests__/test-drive.test.ts` passed 32
tests.
- `pnpm -r typecheck` passed.
- `pnpm build` passed.
- A live literal-key smoke test created one company and one CEO agent
without a provider call.
- A live exported-variable smoke test created the same clean instance
without credential flags.
- `pnpm test:run` completed locally with 5,870 passing tests and 19
host-dependent failures in six unrelated suites. The failures came from
macOS `/tmp` aliases, exhausted test ports, and existing
workspace-runtime fixture assumptions.
- GitHub CI passed the full build, typecheck, canary dry run, general
tests, serialized server tests, and e2e matrix on clean Linux runners.
- Greptile rated the exact latest head 5/5, Superagent passed, and all
review threads are resolved.

## Risks

- A raw value passed through `--api-key` can appear in operating-system
process listings, shell history, or parent-wrapper output before
Paperclip can scrub its own JavaScript argv view. The command warns
about this risk and Paperclip does not print the value.
- The environment snapshot contains the process environment only in
memory for the life of the foreground command.
- This change adds no schema migration and no REST endpoint.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

OpenAI Codex with GPT-5. The exact deployment version and context window
are not exposed to the agent. Extended reasoning, tool use, code
execution, and GitHub access were enabled.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-05 10:48:17 -05:00
..
helpers fix(cli): make embedded-Postgres tests survive runner contention (#12466) 2026-08-28 13:51:54 -07:00
access-parity.test.ts Improve CLI API parity coverage (#6626) 2026-06-02 17:13:29 -07:00
activity-parity.test.ts Improve CLI API parity coverage (#6626) 2026-06-02 17:13:29 -07:00
admin-asset-skill-parity.test.ts Remove cheap model profiles (#12683) 2026-09-01 14:57:38 -05:00
agent-jwt-env.test.ts feat(apps): consolidate connector management (#12684) 2026-09-01 14:55:35 -05:00
agent-lifecycle.test.ts feat(skills): require explicit merge modes (#10978) 2026-08-07 00:42:08 -05:00
allowed-hostname.test.ts feat: implement app-side telemetry sender 2026-04-02 10:47:29 -05:00
auth-command-registration.test.ts fix(cli): handle headless browser-open failure in board auth (#8328) 2026-06-19 08:58:17 -07:00
board-auth.test.ts Add browser-based board CLI auth flow 2026-03-23 08:46:05 -05:00
channels.test.ts feat(cli): add 'paperclipai channels' to show release lanes and the current one (#11210) 2026-08-11 08:47:32 -07:00
common.test.ts test(cli): cover API path construction (#9254) 2026-07-21 09:57:11 -05:00
company-delete.test.ts Remove the company brand color and per-company attachment limit (#12291) 2026-08-27 12:11:05 -07:00
company-export-force.test.ts feat(cli): add --force to company export for non-interactive runs (#10054) 2026-07-22 15:36:54 -07:00
company-import-export-e2e.test.ts feat(decisions): add first-class propose mode (#10010) 2026-07-31 19:17:02 -07:00
company-import-transfer.test.ts feat: already-imported transfer error names the landed company (#12144) 2026-08-25 13:51:50 -07:00
company-import-url.test.ts refactor: rename URL validators to looksLikeRepoUrl 2026-04-01 23:21:22 +00:00
company-import-zip.test.ts Replace host-to-host Cloud Sync with full-fidelity company Import/Export (#10507) 2026-07-30 11:37:00 -07:00
company.test.ts Remove the company brand color and per-company attachment limit (#12291) 2026-08-27 12:11:05 -07:00
config-store.test.ts fix(config): preserve extensions and guard invalid repairs (#11005) 2026-08-07 00:41:19 -05:00
configure-repair.test.ts fix(config): preserve extensions and guard invalid repairs (#11005) 2026-08-07 00:41:19 -05:00
configure.test.ts fix(config): preserve extensions and guard invalid repairs (#11005) 2026-08-07 00:41:19 -05:00
connect.test.ts Improve CLI API parity coverage (#6626) 2026-06-02 17:13:29 -07:00
context.test.ts Improve CLI API parity coverage (#6626) 2026-06-02 17:13:29 -07:00
data-dir.test.ts feat(cli): add --data-dir flag to isolate local state 2026-03-02 14:20:37 -06:00
database-check.test.ts fix: warn when a worktree-mode embedded-postgres data dir is in the OS temp dir (#8283) 2026-08-17 14:02:09 -07:00
doctor.test.ts feat: implement app-side telemetry sender 2026-04-02 10:47:29 -05:00
env-lab.test.ts build(deps): bump @clack/prompts from 0.11.0 to 1.7.0 (#11724) 2026-08-20 15:57:20 -07:00
feedback.test.ts Improve CLI API parity coverage (#6626) 2026-06-02 17:13:29 -07:00
git-workspace.test.ts feat(cli): add isolated test-drive command (#12894) 2026-09-05 09:33:38 -05:00
home-paths.test.ts [codex] Add LLM Wiki plugin host support (#5597) 2026-05-10 07:34:12 -05:00
http.test.ts fix(security): route paperclipai CLI guidance through safe npx form (CWE-78) (#11400) 2026-08-14 22:11:16 -07:00
install-command.test.ts feat(cli): add managed install, update, and service lifecycle (#10045) 2026-07-31 18:52:23 -07:00
install-store.test.ts feat(cli): add managed install, update, and service lifecycle (#10045) 2026-07-31 18:52:23 -07:00
issue-subresources.test.ts fix(cli): send X-Paperclip-Run-Id so agents can mutate their issues via the CLI (#7642) 2026-06-06 15:55:55 -07:00
managed-agent.test.ts feat(runner): add managed provider backends (#12699) 2026-09-02 00:48:30 -05:00
managed-install-check.test.ts feat(cli): add managed install, update, and service lifecycle (#10045) 2026-07-31 18:52:23 -07:00
network-bind.test.ts Fix wrapped company issue prefix conflicts (#6423) 2026-05-22 15:27:54 -05:00
onboard-service.test.ts fix(cli): open dashboard after onboarding service starts (#12164) 2026-08-25 09:33:09 -05:00
onboard.test.ts feat(apps): consolidate connector management (#12684) 2026-09-01 14:55:35 -05:00
open-url.test.ts fix(cli): handle headless browser-open failure in board auth (#8328) 2026-06-19 08:58:17 -07:00
operations-parity.test.ts Improve CLI API parity coverage (#6626) 2026-06-02 17:13:29 -07:00
pipelines.test.ts Add pipeline workflow primitives and operator UI (#7903) 2026-06-26 12:02:44 -05:00
plugin-init.test.ts feat(cli): surface plugin install target host + add `plugin target` (#8575) 2026-06-25 01:07:35 -07:00
project-goal.test.ts feat(mcp) [split 5/8]: integrate adapters and deployment runtime (#9560) 2026-07-14 15:15:43 -05:00
prompt.test.ts test(cli): cover board prompt handoff (#9137) 2026-07-21 10:00:28 -05:00
routine-plugin-parity.test.ts feat(mcp) [split 5/8]: integrate adapters and deployment runtime (#9560) 2026-07-14 15:15:43 -05:00
routines.test.ts feat(routines): add workspace-aware routine runs 2026-04-02 11:38:57 -05:00
run.test.ts Improve CLI API parity coverage (#6626) 2026-06-02 17:13:29 -07:00
runtime-info.test.ts fix(cli): open dashboard after onboarding service starts (#12164) 2026-08-25 09:33:09 -05:00
secrets.test.ts feat(workspaces): sign the workspace login handoff and gate readiness (#11671) 2026-08-19 02:37:02 -05:00
service-health-check.test.ts fix(cli): materialize the managed install before the onboarding service install (#12148) 2026-08-24 23:30:54 -07:00
service-manager.test.ts feat(cli): add managed install, update, and service lifecycle (#10045) 2026-07-31 18:52:23 -07:00
skills.test.ts feat(skills): require explicit merge modes (#10978) 2026-08-07 00:42:08 -05:00
teams.test.ts refactor(deps-dev): bump vitest from 3.2.4 to 4.1.8 (#7581) 2026-06-05 21:11:32 -07:00
telemetry.test.ts test: make cli telemetry test deterministic in CI 2026-04-02 10:47:30 -05:00
test-drive.test.ts fix(cli): restore test-drive credential inputs (#12898) 2026-09-05 10:48:17 -05:00
token.test.ts test(cli): cover board token commands (#9138) 2026-07-21 10:01:15 -05:00
update-command.test.ts feat(cli): add managed install, update, and service lifecycle (#10045) 2026-07-31 18:52:23 -07:00
update-notice.test.ts feat(cli): add managed install, update, and service lifecycle (#10045) 2026-07-31 18:52:23 -07:00
worktree-merge-history.test.ts Add merge-history project import option 2026-03-23 08:14:51 -05:00
worktree.test.ts feat(apps): consolidate connector management (#12684) 2026-09-01 14:55:35 -05:00
zip-codec.test.ts Replace host-to-host Cloud Sync with full-fidelity company Import/Export (#10507) 2026-07-30 11:37:00 -07:00