feat(design-gate): ask for 21st login and wait instead of skipping

The design gate checked the 21st CLI with command -v only, so an
installed-but-signed-out CLI read as READY and every 21st step failed
downstream. tool_active now probes 21st whoami through a three-state
function: signed in (TWENTYFIRST_TOKEN or API_KEY_21ST set, or 'Logged in
as'), signed out (exact 'Not logged in'), unknown (rc != 0, timeout,
unexpected output). Signed out is a new verdict, SIGN-IN REQUIRED, exit
12: design-gate.md tells the orchestrator to ask the user to run
! 21st login, end the turn, re-run the gate on their reply, and to skip
21st only on an explicit 'proceed without 21st', never silently. Unknown
surfaces as exit 11 with the whoami diagnostic and a CLI-runtime remedy,
so a node/PATH failure can never loop on a sign-in prompt. INCOMPLETE
still wins. Hermetic suite lib/tests/design-tool-gate.test.sh (stub CLI,
fixture repo through DESIGN_GATE_REPO_OVERRIDE) covers every state.
This commit is contained in:
bastien
2026-09-28 12:51:55 +02:00
parent 729d71546f
commit bd3e525bb3
6 changed files with 307 additions and 32 deletions
+14
View File
@@ -7,6 +7,20 @@ Format follows [Keep a Changelog](https://keepachangelog.com/).
## [Unreleased]
### Added
- **Design gate asks the user to sign in to 21st instead of skipping it**:
`lib/design-tool-gate.sh` adds a three-state 21st auth predicate
(`twentyfirst_auth_state`, honors `TWENTYFIRST_TOKEN`/`API_KEY_21ST` or a
local `21st whoami` read). Signed out now trips a new `SIGN-IN REQUIRED`
state (exit 12) instead of silently proceeding or reporting a plain
INCOMPLETE. The agent asks the user to run `! 21st login` in-session and
waits, re-running the gate on reply; an explicit "proceed without 21st"
opt-out is honored and never re-asked. A `whoami` answer that can't be
classified (unexpected line, nonzero rc, timeout) surfaces as unverified
with the raw diagnostic (`21st (whoami: rc=… …)`), never guessed as
signed-in or signed-out. `lib/design-gate.md` and the
`skills/feat`/`skills/bugfix` STEP 0.5 design-gate bullets document the
new branch. Hermetic suite `lib/tests/design-tool-gate.test.sh`, 7 named
cases.
- **`make doctor` checks the vendored externals** — new
`lib/doctor-vendored.sh` (`check_vendored_skills`), wired into doctor.sh
after the gstack section: every curl-pinned entry of plugins.lock.json