Origin Grants 与用户委托
管理资源直接授权,并核对 installation user token 的权限交集和撤销延迟。
This page has not been translated into English yet. The original Chinese version is shown below.
Grant 将一个 principal、一个资源和一个 permission 绑定。列表仅返回资源直接 grant,不能把它当成全部继承后的 effective access。
Principal 与权限
user 使用 user_…,group 使用 public grp_…,不同于组织组 API 路径的 g_…;teamGroup 为内置 members/admins。
Repository permission 为 read/write/admin,namespace 为 PERMISSION_READ、PERMISSION_CONTRIBUTOR、PERMISSION_WRITE、PERMISSION_ADMIN。自定义 policy 可在读结果显示 custom/PERMISSION_CUSTOM,但 upsert 不接受,返回 400。
repository:settings:read/write 或 namespace:settings:read/write 控制对应资源。POST upsert 创建或替换该 principal 唯一 grant,重复相同请求不叠加;DELETE 在 body 指定 principal,成功 204。不得删除最后一个 namespace admin。
代表用户执行
workspace admin 可批准 namespace:user_tokens:write,使 installation 为 namespace active members mint user token。每次请求同时受 installation 范围、用户 grants 和 token 缩小范围限制。
可选 user confirmation 只证明当时 user_ ID、邮箱和成员资格,不授予权限,也不是 mint 的必填材料。回执 typ=origin-user-confirmation-receipt+jwt,五分钟有效,需验签和 signed state,并防止 jti 重放;取消确认没有 callback。
Mint 与使用
使用 app JWT POST /app/installations/{installationId}/user_access_tokens,恰好给 userId 或 userEmail。可设 scopes 和最多 50 个唯一 repositoryIds,空/省略继承当前权限;namespace:user_tokens:write 与 app:/installation: scopes 不可委托到 token。
同时指定两种限制时,mint 要求用户和 installation 对每个列出的仓库都具有每项 scope;其他情况在请求时检查。token 最长 15 分钟且不超过 JWT exp,无 refresh token,按 expiresAt 重签。
REST 用 Bearer,Git 用 x-access-token/password。用户仍是 actor,可有 performedVia.app 表示代行;该字段归于所描述的动作,不代表所有后续编辑者。
撤销边界
单个 user token 不能直接撤销。卸载/删除 app、关闭用户账号可提前使其 401;移除 mint scope 或暂停 installation 阻止新 mint,已发 token 到 expiresAt 结束。grant 变更最迟在该期限反映,不能承诺全部既发 token 即时失效。