Add persistent configuration and safe token setup

#30 · open · 0 comments

View on GitHub ↗

damacus

## Problem The CLI currently requires `MEALIE_URL` and `MEALIE_TOKEN` in every shell environment. This is convenient for CI, but cumbersome for daily interactive use and encourages long-lived secrets in shell profiles. ## Proposed scope Add an opt-in persistent setup flow while preserving environment-variable compatibility: - store non-secret configuration under the XDG configuration directory; - add a command to set or update the Mealie URL; - add a token setup command that reads from stdin or a hidden prompt, never a command-line argument; - store the token in an OS credential store where practical, with a clearly documented permission-restricted fallback; - use precedence `flags where safe > environment > selected profile > defaults`; - let `mealie status` report which configuration source is active without revealing the token; - support removing stored credentials cleanly. Profiles may be included if they do not inflate the first implementation; the storage and precedence model should leave room for them. ## Acceptance criteria - A user can configure the CLI once without editing a shell profile. - Tokens never appear in argv, logs, status output, or debug formatting. - Existing environment-only usage and CI remain compatible. - File permissions and config precedence are tested. - Setup, inspection, and removal commands have human and structured output. - Documentation includes migration and uninstall/cleanup instructions.

Comments