跳到正文
FunCoding

搜索

搜索文档、Skill 和 MCP

Origin Grants 与用户委托

管理资源直接授权,并核对 installation user token 的权限交集和撤销延迟。

Grant 将一个 principal、一个资源和一个 permission 绑定。列表仅返回资源直接 grant,不能把它当成全部继承后的 effective access。

Principal 与权限

user 使用 user_…,group 使用 public grp_…,不同于组织组 API 路径的 g_…;teamGroup 为内置 members/admins。

Repository permission 为 read/write/admin,namespace 为 PERMISSION_READ、PERMISSION_CONTRIBUTOR、PERMISSION_WRITE、PERMISSION_ADMIN。自定义 policy 可在读结果显示 custom/PERMISSION_CUSTOM,但 upsert 不接受,返回 400。

repository:settings:read/write 或 namespace:settings:read/write 控制对应资源。POST upsert 创建或替换该 principal 唯一 grant,重复相同请求不叠加;DELETE 在 body 指定 principal,成功 204。不得删除最后一个 namespace admin。

代表用户执行

workspace admin 可批准 namespace:user_tokens:write,使 installation 为 namespace active members mint user token。每次请求同时受 installation 范围、用户 grants 和 token 缩小范围限制。

可选 user confirmation 只证明当时 user_ ID、邮箱和成员资格,不授予权限,也不是 mint 的必填材料。回执 typ=origin-user-confirmation-receipt+jwt,五分钟有效,需验签和 signed state,并防止 jti 重放;取消确认没有 callback。

Mint 与使用

使用 app JWT POST /app/installations/{installationId}/user_access_tokens,恰好给 userId 或 userEmail。可设 scopes 和最多 50 个唯一 repositoryIds,空/省略继承当前权限;namespace:user_tokens:write 与 app:/installation: scopes 不可委托到 token。

同时指定两种限制时,mint 要求用户和 installation 对每个列出的仓库都具有每项 scope;其他情况在请求时检查。token 最长 15 分钟且不超过 JWT exp,无 refresh token,按 expiresAt 重签。

REST 用 Bearer,Git 用 x-access-token/password。用户仍是 actor,可有 performedVia.app 表示代行;该字段归于所描述的动作,不代表所有后续编辑者。

撤销边界

单个 user token 不能直接撤销。卸载/删除 app、关闭用户账号可提前使其 401;移除 mint scope 或暂停 installation 阻止新 mint,已发 token 到 expiresAt 结束。grant 变更最迟在该期限反映,不能承诺全部既发 token 即时失效。