Repository navigation
feat(modules): authenticated module sources — private-registry support - #330
Merged
Merged
Conversation
A module source can now carry a credential REFERENCE (never the raw secret): it names the GitHub
`org` its token covers and an `auth` {type, ref} pointing at the config key that holds the secret.
Tiger_Module_Github gains an org-scoped auth resolver + a testable transport seam, and
Tiger_Module_Registry wires the resolver from the configured authenticated sources (decrypting the
referenced secret) and installs it across all three flows — Add (index/search), update detection
(Tiger_Update_Checker), and apply (Tiger_Module_Installer). An authorized PRIVATE repo is now
readable + installable; with no authenticated source configured everything stays public, and no
shipped-default source is ever authenticated (a guard test enforces it).
Unit tests cover the credential-reference whitelist (a raw secret can't be stored or leaked), the
org-scoped header attachment via the transport seam (in-scope -> Bearer; out-of-scope / none /
throwing -> public), the resolver mapping org->token case-insensitively, and the no-authed-default
guard. Full unit suite green (1034 tests).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ASauLLscjqdsNqBNsx2Typ
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01ASauLLscjqdsNqBNsx2Typ
This was referenced Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Authenticated module sources (private registries)
Lets the Module Manager read and install from a private registry/repo it is authorized for — not just public ones — while a module source stores only a credential reference, never the raw secret.
Anchors (built + tested in order):
Tiger_Module_Source—orgscope +auth{type, ref}; a whitelist drops any raw secret so it can't be stored or surface viatoArray()/ a settings UI.Tiger_Module_Github— org-scopedsetAuthResolver()attachesAuthorization: Beareronly for covered repos; asetTransport()seam makes it testable with no network.Tiger_Module_Registry—authResolver()builds org→token from the configured authed sources (decrypting the referenced secret);ensureAuth()installs it (idempotent) across Add / update detection / install.Safety: with no authenticated source configured, behavior is identical to before (public-only). Private release-ZIP assets (vendored-bundle modules) remain a documented follow-up; source/theme private repos install from the authenticated tarball.
Tests: full unit suite green (1034 tests, 17,725 assertions); new coverage in SourceTest / GithubTest / RegistryTest.
🤖 Generated with Claude Code
https://claude.ai/code/session_01ASauLLscjqdsNqBNsx2Typ