Build an apex-scoped [`StorageClient`] authenticating as a **named identity rather than whichever one the server profile resolves to. Agent enrollment is the reason this exists: the caller must be the human who signs the certificate, and that is not necessarily the identity bound to the profile — nor, once agents are in play, the default. Making the identity explicit keeps "who is enrolling" a de
(
identity: &atomic_identity::Identity,
server_override: Option<&str>,
)
| 166 | /// explicit keeps "who is enrolling" a decision at the call site instead of a |
| 167 | /// side effect of configuration. |
| 168 | pub async fn build_apex_client_as( |
| 169 | identity: &atomic_identity::Identity, |
| 170 | server_override: Option<&str>, |
| 171 | ) -> CliResult<(StorageClient, String)> { |
| 172 | let apex_url = apex_server_url(server_override)?; |
| 173 | let bearer_token = crate::commands::token::get_token(&apex_url, identity).await?; |
| 174 | let delegation = delegation_for(identity, &apex_url); |
| 175 | |
| 176 | let client = |
| 177 | StorageClient::with_delegation(&apex_url, "", &bearer_token, delegation.as_deref()) |
| 178 | .map_err(|e| { |
| 179 | CliError::Internal(anyhow::anyhow!("Failed to create storage client: {}", e)) |
| 180 | })?; |
| 181 | |
| 182 | Ok((client, apex_url)) |
| 183 | } |
| 184 | |
| 185 | /// Build a [`StorageClient`] and return the resolved org slug alongside it. |
| 186 | /// |
no test coverage detected