This adds a headless authentication path for tg while preserving the existing browser-based OAuth flow.
tg auth login <handle> <app-password> now authenticates through the AT Protocol password-session API and persists the resulting access and refresh tokens with user-only file permissions. Persisted sessions resume across invocations, refresh-token updates are saved automatically, and tg auth token, tg auth status, and tg auth logout work with both authentication methods.
The README now documents OAuth login, app-password login, credential storage, and logout behavior.
This also fixes tg repo fork. The command previously passed an at:// record URI as the knotโs clone source, causing the knot to reject it as an invalid URL. It now sends the expected https://<knot>/<repoDid> source URL and records the upstream AT URI as fork metadata. A regression test covers source URL construction.
Validation:
go test ./...go build ./cmd/tg- Live app-password login, persistence, token retrieval, and logout
- Live fork of
aly.codes/tgtookami.mom/tg-app-password-auth
this pr was written with 5.6-luna as a way to live test PRing with this PR
ty ana!