mirror of
https://github.com/tiennm99/ghglance.git
synced 2026-10-11 03:13:20 +00:00
feat(web): require GitHub sign-in to generate cards
The web UI now runs every job on an OAuth token from "Sign in with GitHub". The ticked options decide the requested scopes (read:user, plus repo for private repos, plus read:org for org repos); a grant wider than requested is refused. The token lives only on the job and is revoked when the job ends, on every path including shutdown. The server no longer holds a GitHub token of its own, and the pasted-token field and /generate are gone. -serve requires -oauth-client-id, -oauth-client-secret and -public-url (GHGLANCE_OAUTH_* and GHGLANCE_PUBLIC_URL), and compose.yml requires them too. The CLI and the Action keep -token unchanged.
This commit is contained in:
1 parent
3b157e4215
commit
2def27f49a
17 files changed
+1599
-406
No files matched your search
+5
-1
@@ -1 +1,5 @@
|
||||
GHGLANCE_TOKEN=
|
||||
# "Sign in with GitHub" (a GitHub OAuth App); all three are required.
|
||||
GHGLANCE_OAUTH_CLIENT_ID=
|
||||
GHGLANCE_OAUTH_CLIENT_SECRET=
|
||||
# External origin; the OAuth App's callback URL is <this>/auth/callback.
|
||||
GHGLANCE_PUBLIC_URL=
|
||||
Reference in new issue
Block a user