Longbridge CLI 0.17.0 (verified locally) provides everything needed for an in-app, no-terminal connect flow:
longbridge auth login --format json— Device Authorization Flow (RFC 8628) by default: prints averification_uri, the user opens it in ANY browser, the CLI polls until authorized. No localhost callback needed. (--auth-codeflow exists but requires a browser on the same machine and a localhost listener — do not use.)longbridge auth status --format json→{ account: { account_no, account_type, member_id, name, quote_level }, token: { logged_in_at, path, status: "valid" | … } }— the connection-health and permission source.quote_levelencodes per- market entitlement (e.g.USAB:…|Global|Delay= delayed US quotes;HKAA:…|Global|LV2= HK level-2). Parse it intoProviderPermission[].longbridge auth logout— clear stored token (Disconnect).longbridge check --format json→{ connectivity: {cn, global}, region: {active}, session: {token, detail} }— Test Connection + diagnostics.longbridge --version→longbridge 0.17.0— install state + diagnostics.
Connections → Longbridge → Connect→ main runslongbridge auth login --format json, parsesverification_uri, opens it withshell.openExternal, reportsconnecting.- Main polls
longbridge auth status --format json(e.g. every 3s, timeout 180s) untiltoken.status === 'valid'→connected+ health snapshot (account identity, permissions, region). - Timeout / user cancel → kill the login process, status
not-connected(orexpiredif a token previously existed). - Disconnect →
longbridge auth logout→not-connected. - CLI missing →
not-installed; UI shows [Install / Setup] that opens the official Longbridge setup docs (never curl|sh).
Renderer NEVER spawns a shell; all CLI interaction stays in the main process (same pattern as the existing executor).
- token missing →
not-connected - login in flight →
connecting - token valid, all expected entitlements present →
connected - token valid, quote_level shows Delayed-only or missing markets →
permission-limited(permissions[] carries the detail) - token status not valid (expired/revoked) →
expired - status/check command failure →
error(message user-safe)
quote_level values are market-prefixed (SHAB/HKAB/USAB/SZAD/…). Map the
well-known prefixes to markets (US/HK/CN/SG) and treat Delay/LV0 as
delayed-permission entries. Unknown values: pass through as granted=false
with the raw label — never fabricate.