Repository navigation
feat: connect Knotree Registry account once (backend) - #6
Merged
Merged
Conversation
…deploy Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Backend for Vercel-style deploys from Knotree Registry. The user connects their Registry account once. After that they can only list and deploy images from their own namespace, and auto-deploys are tied to their Knotree Accounts identity.
Depends on vantanminh/knotree-registry#4.
knotree_registry_accounts(one active row per user),registry_account_consent_attempts, andknotree_registry_connections.account_id.registry_accounts.rs:POST /integrations/knotree-registry/authorize: namespace consent. It is SSO-subject bound and reuses the PKCE/session-bound callback.GET/DELETE /integrations/knotree-registry: connection status and disconnect. Disconnecting revokes derived connections and turns off auto-deploy.GET /integrations/knotree-registry/repositories[/{repo}]: the image picker. It only ever uses the signed-in user's own credential and filters results to their namespace.POST .../registry-connections/from-account: creates or reuses a project connection, which the existing app-service flow then uses.load_credentials: account-derived connections always use the account's live credential, so reconnecting renews every project. PAT rotation is blocked on derived connections.owner_issuer/owner_subjectmatch the connected account. The connection repository must also match the pushed repository.Not in this PR: the web UI (Integrations page and Import wizard).
Test plan
cargo test registry). DB-backed tests were skipped because there was no local Postgres.🤖 Generated with Claude Code