Note that rerunning failed tests is web UI only - #1765
Closed
mattmenefee wants to merge 1 commit into
Closed
mattmenefee wants to merge 1 commit into
mattmenefee wants to merge 1 commit into
Conversation
The job page in the web UI offers four rerun actions; only two have CLI equivalents. Neither the help text nor the command tree distinguished "not built yet" from "not possible here", so anyone looking for the narrower rerun had to go searching to learn it was not there. That action is served by an endpoint scoped to the web app's own session. A personal API token authenticates against it but reads no data, and a token from circleci auth login is rejected outright: the resource advertises app.circleci.com as its issuer, while the CLI authenticates against circleci.com. No credential the CLI holds today reaches it, so the help now says so and points at the docs rather than leaving the reader to find out the hard way. The opening paragraph is compressed to hold the rendered help inside the 40-line budget TestHelp enforces.
Contributor
|
Hi @mattmenefee, Thanks for opening this. This is now supported via the I'll keep the issue open in case you run into any issues onboarding with the new testing tool. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
circleci workflow rerun --helpnow states that rerunning only the failed tests — the web UI's "Rerun failed tests" — has no CLI or public API equivalent, and links to the docs.Longso the rendered help stays within the 40-line budgetTestHelpenforces (now exactly 40/40, nooverBudgetentry added).Refs #1659. This closes the documentation half of that issue — "There's nothing in the help output or the command tree that distinguishes 'not built yet' from 'not possible here'." The feature itself is left to the CircleCI team, for the reason below.
Why the flag isn't implemented here
The intended change was
circleci workflow rerun <workflow-id> --failed-tests. The action is served byPOST /private/tests-plugin-manager/rerun-failed-tests/{workflowId}onapp.circleci.com, with eligibility atGET .../{workflowId}/job/{jobId}returning{"can_rerun_failed_tests": true}.That endpoint is scoped to the web app's own session. Probing the same job-scoped URL the browser itself calls, on a workflow the UI reports as eligible:
Bearerwww-authenticate/api/v3)Invalid token provided.Not found— authenticates, but reads no data{"can_rerun_failed_tests":true}The 401 is an issuer mismatch. Per RFC 9728 metadata the resource advertises
app.circleci.comas its authorization server, while the CLI runs its OAuth flow againstcfg.EffectiveHost()—circleci.com(internal/cmd/cmdauth/login.go:110,internal/oauth/login.go:149-151). The web app also setsincludeApiKeyWhenAvailable: falseon this call, so it depends on the cookie by design.Any one of these would unblock a CLI implementation:
/private/tests-plugin-manager/rerun-failed-tests/*— they already clear the gateway (404, not 401)./api/v3oncircleci.com, where the CLI already authenticates. Preferred: needs no auth change and no app-host client.app.circleci.com-issued token. That AS advertisesauthorization_code+ PKCE (S256) + PAR, whichinternal/oauthalready implements — but a second token for a second issuer is an auth and security decision.Test plan
go test ./... -count=1— 32 packages pass, includingacceptancego test github.com/CircleCI-Public/circleci-cli/clikit/... -count=1— 8 packages passgolangci-lint run ./internal/cmd/workflow/... ./internal/cmd/root/...— 0 issuesgo test ./internal/cmd/root/... -update, not hand-writtencircleci workflow rerun --helprenders at exactly 40 lines, withinhelpLineBudget-race— pre-existing failure inTestDeprecationWarning_SunsetInOutput(data race atacceptance/deprecation_test.go:48). Reproduced onmainat 2407ffd with this change absent, so it is unrelated and not addressed here.