Build a [`StorageClient`] targeting the server **apex** (no org subdomain). Apex-scoped endpoints — notably `GET /orgs` ("list my orgs") and `POST /orgs` ("create org") — span orgs, so they must be hit on the bare server host rather than an ` . ` subdomain. This helper resolves the active server profile, mints a self-signed EdDSA JWT against the apex URL, and constructs a `StorageClient`
(server_override: Option<&str>)
| 80 | /// - Identity store cannot be opened or no default identity set. |
| 81 | /// - HTTP client construction failure. |
| 82 | pub async fn build_apex_client(server_override: Option<&str>) -> CliResult<StorageClient> { |
| 83 | let config = GlobalConfig::load() |
| 84 | .map_err(|e| CliError::Internal(anyhow::anyhow!("Failed to load global config: {}", e)))?; |
| 85 | |
| 86 | let server = config |
| 87 | .resolve_server(server_override) |
| 88 | .map_err(|e| CliError::Internal(anyhow::anyhow!("{}", e)))? |
| 89 | .0; |
| 90 | |
| 91 | let apex_url = server |
| 92 | .url |
| 93 | .clone() |
| 94 | .ok_or_else(|| server_url_missing(server_override))?; |
| 95 | |
| 96 | let identity = resolve_identity_for_server(server)?; |
| 97 | |
| 98 | // Self-signed EdDSA JWT keyed by the identity's own public key; minted |
| 99 | // against the apex URL (the token is portable across the deployment). |
| 100 | let bearer_token = crate::commands::token::get_token(&apex_url, &identity).await?; |
| 101 | |
| 102 | let delegation = delegation_for(&identity, &apex_url); |
| 103 | let client = |
| 104 | StorageClient::with_delegation(&apex_url, "", &bearer_token, delegation.as_deref()) |
| 105 | .map_err(|e| { |
| 106 | CliError::Internal(anyhow::anyhow!("Failed to create storage client: {}", e)) |
| 107 | })?; |
| 108 | |
| 109 | Ok(client) |
| 110 | } |
| 111 | |
| 112 | /// The encoded certificate this identity presents, if it is an agent. |
| 113 | /// |
no test coverage detected