Expand description
Registering the community’s GitHub App through the manifest flow (§5.7).
The bridge builds a manifest; the admin’s browser POSTs it to GitHub (a
form whose manifest field is the JSON below) at the URL from
registration_url; the admin approves; GitHub redirects to
redirect_url with a one-time code; exchange_code trades it for
the App’s id, private key and webhook secret. Nobody copies a key by hand.
The permission set is fixed here, not a parameter, so every community’s
App asks for the same reviewed set. The manifest travels through the
admin’s browser, where it could be altered, so exchange_code checks
that the App GitHub actually registered holds nothing beyond these
permissions and refuses the credentials otherwise.
GitHub’s manifest format cannot enable the OAuth device flow; the admin
ticks “Enable Device Flow” on the App’s settings page once, or account
linking reports device_flow_disabled.
Structs§
- AppCredentials
- What registering the App produced. Holds the App private key and the
webhook and client secrets: zeroized on drop, never
Debug-printed. - Manifest
Params - Inputs to the manifest.
Constants§
- APP_
EVENTS - Webhook events for drift (§5.6), plus
organizationfor members joining and leaving the org,pull_request/merge_group/check_run/check_suiteso the bridge can post (and re-post, on a rerequest) the check where it runs it itself, andpushfor the Dependabot re-sign’s provenance ledger (RESIGN_EVENTS).installationevents are always delivered to an App and need no subscription. Sorted. - APP_
PERMISSIONS - The App’s permissions: repository Administration (write), Contents (write, for the bootstrap commit and for pushing re-signed Dependabot commits, §9), Variables (write), Metadata (read); organisation Members (read) and Administration (write). No secrets, Actions logs, code scanning or packages.
- CHECK_
EVENTS - The events the bridge-posted check is triggered by (see
CHECK_PERMISSIONS). - CHECK_
PERMISSIONS - What the bridge-posted check needs on an installation: the permissions and the event subscriptions. An App registered before these were in the manifest has neither until its settings are changed and each installation’s owner approves the change — until then the namespace keeps the in-repo Actions workflow.
- RESIGN_
EVENTS - The events the Dependabot re-sign needs (§9, “Dependabot re-sign bot”):
push, the signed record of who moved eachdependabot/*branch, from which the bridge decides whether a branch is Dependabot’s alone. GitHub delivers it under Contents, which the App already holds (write, for the bootstrap commit and the re-signed push). An App registered beforepushwas in the manifest sees no pushes, so no branch is ever clean and nothing is re-signed until the owner subscribes it — failing safe.
Functions§
- app_
manifest - The manifest JSON.
- check_
ready - Whether an installation with
grantedpermissions andeventssubscriptions can carry the bridge-posted check. - exchange_
code - Exchange the redirect’s
codefor the App’s credentials (POST /app-manifests/{code}/conversions). The code is single-use and expires after an hour. - registration_
url - Where the admin’s browser POSTs the manifest form: the org’s settings
when
orgis given (the App is then owned by the org), the admin’s own otherwise.statecomes back on the redirect; check it there.