Skip to content

feat(modules): authenticated module sources — private-registry support - #330

Merged
WebTigers merged 2 commits into
mainfrom
feat/authenticated-module-sources
Oct 8, 2026
Merged

WebTigers merged 2 commits into
mainfrom
feat/authenticated-module-sources

Conversation

@WebTigers

Copy link
Copy Markdown
Owner

Authenticated module sources (private registries)

Lets the Module Manager read and install from a private registry/repo it is authorized for — not just public ones — while a module source stores only a credential reference, never the raw secret.

Anchors (built + tested in order):

  1. Tiger_Module_Source — org scope + auth {type, ref}; a whitelist drops any raw secret so it can't be stored or surface via toArray() / a settings UI.
  2. Tiger_Module_Github — org-scoped setAuthResolver() attaches Authorization: Bearer only for covered repos; a setTransport() seam makes it testable with no network.
  3. Tiger_Module_Registry — authResolver() builds org→token from the configured authed sources (decrypting the referenced secret); ensureAuth() installs it (idempotent) across Add / update detection / install.
  4. Guard — no shipped-default source is ever authenticated (private feeds are admin-config only), and a raw secret can't be stored on a source.

Safety: with no authenticated source configured, behavior is identical to before (public-only). Private release-ZIP assets (vendored-bundle modules) remain a documented follow-up; source/theme private repos install from the authenticated tarball.

Tests: full unit suite green (1034 tests, 17,725 assertions); new coverage in SourceTest / GithubTest / RegistryTest.

🤖 Generated with Claude Code

https://claude.ai/code/session_01ASauLLscjqdsNqBNsx2Typ

WebTigers and others added 2 commits October 8, 2026 07:59
A module source can now carry a credential REFERENCE (never the raw secret): it names the GitHub
`org` its token covers and an `auth` {type, ref} pointing at the config key that holds the secret.
Tiger_Module_Github gains an org-scoped auth resolver + a testable transport seam, and
Tiger_Module_Registry wires the resolver from the configured authenticated sources (decrypting the
referenced secret) and installs it across all three flows — Add (index/search), update detection
(Tiger_Update_Checker), and apply (Tiger_Module_Installer). An authorized PRIVATE repo is now
readable + installable; with no authenticated source configured everything stays public, and no
shipped-default source is ever authenticated (a guard test enforces it).

Unit tests cover the credential-reference whitelist (a raw secret can't be stored or leaked), the
org-scoped header attachment via the transport seam (in-scope -> Bearer; out-of-scope / none /
throwing -> public), the resolver mapping org->token case-insensitively, and the no-authed-default
guard. Full unit suite green (1034 tests).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ASauLLscjqdsNqBNsx2Typ
@WebTigers
WebTigers merged commit c40438a into main Oct 8, 2026
14 checks passed
@WebTigers
WebTigers deleted the feat/authenticated-module-sources branch October 8, 2026 13:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant