mirror of
https://github.com/tiennm99/ghglance.git
synced 2026-10-11 03:13:20 +00:00
The web UI now runs every job on an OAuth token from "Sign in with GitHub". The ticked options decide the requested scopes (read:user, plus repo for private repos, plus read:org for org repos); a grant wider than requested is refused. The token lives only on the job and is revoked when the job ends, on every path including shutdown. The server no longer holds a GitHub token of its own, and the pasted-token field and /generate are gone. -serve requires -oauth-client-id, -oauth-client-secret and -public-url (GHGLANCE_OAUTH_* and GHGLANCE_PUBLIC_URL), and compose.yml requires them too. The CLI and the Action keep -token unchanged.
6 lines
220 B
Bash
6 lines
220 B
Bash
# "Sign in with GitHub" (a GitHub OAuth App); all three are required.
|
|
GHGLANCE_OAUTH_CLIENT_ID=
|
|
GHGLANCE_OAUTH_CLIENT_SECRET=
|
|
# External origin; the OAuth App's callback URL is <this>/auth/callback.
|
|
GHGLANCE_PUBLIC_URL=
|