Skip to content

feat(sources): shared-registration mode, admin-consent link, ADR-012 amendment (CONTRACT EDIT FOR OWNER REVIEW) - #60

Merged
urnlahzer merged 1 commit into
mainfrom
feat/shared-registration-ui
Oct 2, 2026
Merged

urnlahzer merged 1 commit into
mainfrom
feat/shared-registration-ui

Conversation

@urnlahzer

Copy link
Copy Markdown
Owner

What

Third slice of PR-1 in docs/plans/2026-09-27-google-provider-and-shared-registration.md, on top of #59: the Sources screen's shared-registration mode, the admin-consent link, the ADR-012 amendment, and the user docs.

Contract edit for owner review: docs/adr/ADR-012-distribution-and-registration.md gains an additive amendment (no existing sentence changed) recording build-time injection (OPENLOOPS_MS_CLIENT_ID, OPENLOOPS_GOOGLE_CLIENT_ID, OPENLOOPS_GOOGLE_CLIENT_SECRET via option_env!) as the enablement switch for the shared registration, while tracked configuration stays placeholder-only and every source build stays BYO-only. The JSON contracts and capability states are untouched (the evidence, protected-state and governance checkers pin every capability as disabled). The only checker change is the ADR hash literal.

UI

  • With a shipped registration (release builds only): helper text; a read-only monospace Admin consent link field plus Open admin consent page while the client-ID field is empty; the client-ID field and Open Microsoft Entra inside Use my organization's own registration (optional).
  • Without one (every source build today): unchanged.
  • The card branches on a property set once per launch, so typing in the client-ID field does not re-render the card (an earlier draft lost focus on the first keystroke; caught in review).
  • Field gains a read-only passthrough; no new component types.

Verification

  • cargo fmt --all -- --check, clippy -D warnings (native-ui,ui-screenshot): clean
  • cargo test -p openloops-desktop --features native-ui -- --test-threads=1: 438 passed, 0 failed, 3 ignored
  • tools/check-distribution-registration-boundary.ps1: P0-DIST-CROSS-CONTRACT-001 passes with the re-pinned hash; only the pre-existing P0-DIST-INVENTORY-001 (product-spec/plan/traceability hash drift from earlier PRs) fails, as on main.
  • Cargo.lock unchanged; public-repo gate passed on the staged files.
  • Read-only Opus review, then a fix pass (focus-loss bug, vacuous test, docs heading, wording).

Owner actions (free, outside the code)

Publisher verification: Partner Center account in the Microsoft AI Cloud Partner Program, DNS-verified custom domain as the registration's publisher domain, Partner One ID entered on the registration, a second registration owner. Release builds then set OPENLOOPS_MS_CLIENT_ID. Until then the app behaves exactly as today.

🤖 Generated with Claude Code

https://claude.ai/code/session_01YCesN8ZHnhqa6n3rWFThas

…amendment (CONTRACT EDIT FOR OWNER REVIEW)

Third slice of PR-1 in docs/plans/2026-09-27-google-provider-and-shared-registration.md,
on top of #59.

- Sources card 1 branches on whether the build carries a shipped Microsoft registration
  (a property set once from registration::microsoft(), so typing in the client-ID field no
  longer re-renders the card and loses focus). With one: helper text; a read-only
  monospace "Admin consent link" Field and "Open admin consent page" (reusing the open-entra
  callback) shown while the BYO field is empty; the BYO client-ID field inside a
  "Use my organization's own registration (optional)" disclosure with "Open Microsoft
  Entra" (new open-entra-portal callback). Without one: today's layout.
- Field gains a read-only passthrough to LineEdit/TextEdit; no new component types.
- on_open_entra opens the admin-consent URL only when the shared registration is active
  and the URL passes a gate allowing exactly the login.microsoftonline.com origin
  (debug-asserted); otherwise the Entra portal. shared_registration_active_for() is a pure
  helper with its own tests (empty / whitespace / non-empty field; no shipped id).
- ADR-012: additive "Amendment (2026-10-02): shared-registration mechanism" describing
  build-time injection as the enablement switch while tracked configuration stays
  placeholder-only; no existing sentence changed. tools/check-distribution-registration-
  boundary.ps1: only the ADR hash literal re-pinned; P0-DIST-CROSS-CONTRACT-001 passes;
  the pre-existing P0-DIST-INVENTORY-001 failure is unchanged. JSON contracts untouched.
- docs/native-setup.md and docs/live-connection.md describe the two modes, the
  "Need admin approval" screen, the unreachable localhost page after consent, and the
  three build-time variables (source builds without them stay BYO-only).

Verified: cargo fmt --check; clippy -D warnings (desktop native-ui,ui-screenshot);
desktop 438 passed, 0 failed, 3 ignored; distribution checker as above;
Cargo.lock unchanged; public-repo gate on staged files.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YCesN8ZHnhqa6n3rWFThas
@urnlahzer
urnlahzer merged commit d474309 into main Oct 2, 2026
2 checks passed
@urnlahzer
urnlahzer deleted the feat/shared-registration-ui branch October 2, 2026 21:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant