Skip to content

feat(worker): hosted identity service — zero-config agentdiff[bot] tokens - #38

Merged
lostmartian merged 1 commit into
mainfrom
feat/token-service
Aug 31, 2026
Merged

lostmartian merged 1 commit into
mainfrom
feat/token-service

Conversation

@lostmartian

Copy link
Copy Markdown
Collaborator

What

A stateless Cloudflare Worker (free tier) that mints 1-hour GitHub App installation tokens, plus a three-tier identity ladder in the generated approve workflow: self-managed App secrets → hosted token service → github-actions[bot]. Each tier is automatic and degrades gracefully — a repo with no App configured still gets the full zero-setup bot (PR #37).

Why

Completes the CodeRabbit-tier UX at $0: install the App once → the bot is branded agentdiff[bot] everywhere, no secrets or variables per repo. The Worker holds the App key; it stores nothing (no KV/DB/logs) and the security contract is enforced in code: caller's Actions token must already have access to the claimed repo, the App must be installed there, tokens expire in ≤1h.

How

  • worker/src/worker.js: POST /token (verify caller → app JWT via WebCrypto RS256 with PKCS#1→PKCS#8 DER normalization — GitHub issues PKCS#1 PEMs — → installation check → mint), GET /app (install redirect), GET / (health)
  • init_wizard.py: TOKEN_SERVICE_URL constant baked into templates; token-selection step chain
  • worker/README.md: deploy + GitHub App permission checklist (user-run, browser steps)
  • Static contract tests (test_token_service.py): routes, security invariants, stateless config, template ladder — plus full YAML validation

Testing

  • 6 new tests; full suite 429 green; lint clean
  • Live behavior verified post-deploy (smoke tests in worker/README.md) — Worker deploy + App creation are user-run browser/console steps by design

Checklist

  • make lint + full suite green
  • CHANGELOG [Unreleased] entry
  • No stored state, no user data, no paid infrastructure

Links to context/ROADMAP.md Phase M / 0.5.0 (user decision: pull K3-lite forward — identity service only, not a hosted eval backend).

…kens

Stateless Cloudflare Worker (free tier) that mints 1h installation
tokens for the project's AgentDiff App: verifies the caller's Actions
token against the claimed repo, confirms the App is installed, mints,
returns. No storage, no logs. Generated workflows now pick identity
from three tiers — self-managed App secrets, hosted service, or
github-actions[bot] — degrading gracefully. Deployment checklist in
worker/README.md.
@lostmartian
lostmartian merged commit cc65494 into main Aug 31, 2026
7 checks passed
@lostmartian
lostmartian deleted the feat/token-service branch August 31, 2026 19:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant