You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 521a1f5
Browse filesBrowse the repository at this point in the historyBrowse files
Lets extensions be published from git/CI instead of the web form. The only
backend gap was headless auth, so this adds long-lived publisher API tokens:
- migration 0005_publisher_tokens (stores only the sha256 of the token)
- mint/list/revoke endpoints; minting requires a real session (a leaked CI
token can't mint more); store currentUser() resolves `tbpub_…` bearers
- scripts/publish-extension.sh: zip → scp to files.profullstack.com → register
the new version via the API with the token (generic; any CI)
- docs/ci-publishing.md: token + SSH-key setup and a paste-in GitHub workflow
scp upload + the version endpoint + slug lookup already existed, so CI reuses
them. Typecheck clean; token mint/resolve/list/revoke round-trip verified.
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
0 commit comments