Files
pmg/config/cobra.go
T
Sahil BansalandGitHub d1dd2560a4 feat: consolidate proxy config into structured section and add support for custom commands to skip proxy (#240)
* feat: add ProxyConfig struct with per-PM skip_commands and legacy fallback

* feat: consolidate proxy config into structured section with backward compat

Replaces flat proxy_mode/proxy_install_only keys with a structured proxy
section supporting per-package-manager skip_commands. Legacy keys are
respected via fallback when user's config lacks the new proxy section.
Removes deprecated experimental_proxy_mode config and flag.

* fix: env var resolution for nested config keys and deduplicate skip command matching

- Add "." to "_" in Viper env key replacer so nested keys like
  sandbox.enabled resolve from PMG_SANDBOX_ENABLED (was silently broken)
- Export IsFirstNonFlagArgInList and remove duplicate from proxy_flow.go
- Add table-driven tests for skip command matching with real-world cases
- Remove redundant env var test

* docs: update proxy configuration and env var documentation

Update config.md env var table to reflect new proxy.enabled and
proxy.install_only keys. Add proxy configuration section to proxy.md
covering config structure, per-PM skip commands, CLI flags, and env vars.

* fix: legacy fallback precedence
2026-05-06 18:27:23 +05:30

72 lines
3.4 KiB
Go

package config
import (
"fmt"
"github.com/spf13/cobra"
)
var skipDependencyCooldown bool
// sandboxAllowRaw holds the raw --sandbox-allow flag values before parsing.
var sandboxAllowRaw []string
// ApplyCobraFlags applies the cobra flags to the command.
// These flags are local concern of the config package. This helper function is used
// to bind them to the Cobra. The default values are taken from the global configuration,
// allowing for overriding the configuration at runtime.
func ApplyCobraFlags(cmd *cobra.Command) {
cmd.PersistentFlags().BoolVar(&globalConfig.Config.Transitive, "transitive",
globalConfig.Config.Transitive, "Resolve transitive dependencies")
cmd.PersistentFlags().IntVar(&globalConfig.Config.TransitiveDepth, "transitive-depth",
globalConfig.Config.TransitiveDepth, "Maximum depth of transitive dependencies to resolve")
cmd.PersistentFlags().BoolVar(&globalConfig.Config.IncludeDevDependencies, "include-dev-dependencies",
globalConfig.Config.IncludeDevDependencies, "Include dev dependencies in the dependency graph (slows down resolution)")
cmd.PersistentFlags().BoolVar(&globalConfig.DryRun, "dry-run",
globalConfig.DryRun, "Dry run skips execution of package manager")
cmd.PersistentFlags().BoolVar(&globalConfig.Config.Paranoid, "paranoid",
globalConfig.Config.Paranoid, "Enable high-security defaults (treat suspicious as malicious)")
cmd.PersistentFlags().BoolVar(&globalConfig.Config.SkipEventLogging, "skip-event-log",
globalConfig.Config.SkipEventLogging, "Skip event logging")
cmd.PersistentFlags().BoolVar(&globalConfig.Config.Proxy.Enabled, "proxy-mode",
globalConfig.Config.Proxy.Enabled, "Use proxy based interception")
cmd.PersistentFlags().BoolVar(&globalConfig.Config.Sandbox.Enabled, "sandbox",
globalConfig.Config.Sandbox.Enabled, "Enable sandbox mode to isolate package manager processes (EXPERIMENTAL)")
cmd.PersistentFlags().BoolVar(&globalConfig.Config.Sandbox.EnforceAlways, "sandbox-enforce",
globalConfig.Config.Sandbox.EnforceAlways, "Apply sandbox to all commands, not just install commands (requires --sandbox)")
cmd.PersistentFlags().StringVar(&globalConfig.SandboxProfileOverride, "sandbox-profile",
globalConfig.SandboxProfileOverride, "Override sandbox policy profile (built-in name or path to custom YAML)")
cmd.PersistentFlags().StringArrayVar(&sandboxAllowRaw, "sandbox-allow",
nil, "Add runtime sandbox allow rule (type=value). Types: read, write, exec, net-connect, net-bind")
cmd.PersistentFlags().BoolVar(&skipDependencyCooldown, "skip-dependency-cooldown",
false, "Skip dependency cooldown enforcement")
}
// FinalizeDependencyCooldownOverride disables dependency cooldown in the global
// config when --skip-dependency-cooldown is set. Must be called after cobra
// flag parsing is complete.
func FinalizeDependencyCooldownOverride() {
if skipDependencyCooldown {
globalConfig.Config.DependencyCooldown.Enabled = false
}
}
// FinalizeSandboxAllowOverrides parses the raw --sandbox-allow flag values
// and stores the validated overrides in the global config. This must be called
// after cobra flag parsing is complete (e.g., in PersistentPreRun).
func FinalizeSandboxAllowOverrides() error {
if len(sandboxAllowRaw) == 0 {
return nil
}
overrides, err := parseSandboxAllowOverrides(sandboxAllowRaw)
if err != nil {
return fmt.Errorf("failed to parse --sandbox-allow flags: %w", err)
}
globalConfig.SandboxAllowOverrides = overrides
return nil
}