🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

ttctl

Package Overview
Dependencies
Maintainers
1
Versions
23
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

ttctl - npm Package Compare versions

Comparing version
0.1.1
to
0.2.0
+5
-5
package.json
{
"name": "ttctl",
"version": "0.1.1",
"version": "0.2.0",
"description": "Unofficial CLI and MCP server for the Toptal Talent platform",

@@ -46,8 +46,8 @@ "type": "module",

"dependencies": {
"@ttctl/cli": "^0.1.1",
"@ttctl/mcp": "^0.1.1"
"@ttctl/cli": "^0.2.0",
"@ttctl/mcp": "^0.2.0"
},
"devDependencies": {
"@types/node": "^25",
"eslint": "^10.4.1",
"@types/node": "^26",
"eslint": "^10.7.0",
"typescript": "~6.0.3",

@@ -54,0 +54,0 @@ "vitest": "^4.1.9",

@@ -205,2 +205,24 @@ # TTCtl

#### Form A2 — per-field 1Password references (signin populates `auth.token`)
```yaml
# username and password each resolve from their own field-level op:// ref
auth:
credentials:
username: "op://Personal/ttctl/username"
password: "op://Personal/ttctl/password"
# account prefix works on field refs too (parity with Form A)
auth:
credentials:
username: "op://my-account/Personal/ttctl/username"
password: "op://my-account/Personal/ttctl/password"
```
When `credentials` is an **object of two `op://` field references**, TTCtl runs `op read --no-newline [--account ACCOUNT] op://VAULT/ITEM/FIELD` once per field. `op read` resolves the field by id or label, so the canonical `username` / `password` field ids work even on browser-autosaved LOGIN items. The optional leading `ACCOUNT` is split off and forwarded as `--account`, for parity with Form A.
> A 4-segment field ref is always read as **account-prefixed** (`op://account/vault/item/field`). 1Password **sectioned** references (`op://vault/item/section/field`, also 4 segments) are therefore **not supported** — the section would be mis-taken as the account. Store the credential field at the item top level (LOGIN items do this by default).
**Routing is by container shape, never by segment count** (`op://a/b/c` is account/vault/item as a bare string but vault/item/field as an object value). A bare-string `credentials` value is always single-item (Form A), item-level only. An object value is per-field (this form) when its values are `op://` refs, or literal (Form B) when they are an email/password pair.
#### Form B — literal credentials (dev/testing only)

@@ -217,3 +239,3 @@

> **Per-field references (4+ segments, e.g. `op://Personal/ttctl/Section/username`) are NOT supported.** The schema rejects them. Use Form A (item-level reference) — TTCtl always reads both USERNAME and PASSWORD fields from a single LOGIN item.
> **Item-level (Form A) vs per-field (Form A2).** Form A reads both USERNAME and PASSWORD from one LOGIN item; Form A2 points each credential at its own field. A bare-string reference with a `/field` suffix is rejected — per-field requires the object shape (one string cannot carry two references).

@@ -220,0 +242,0 @@ #### Form C — token only (out-of-band bootstrap)