Repository navigation
feat(sources): shared-registration mode, admin-consent link, ADR-012 amendment (CONTRACT EDIT FOR OWNER REVIEW) - #60
Merged
Conversation
…amendment (CONTRACT EDIT FOR OWNER REVIEW) Third slice of PR-1 in docs/plans/2026-09-27-google-provider-and-shared-registration.md, on top of #59. - Sources card 1 branches on whether the build carries a shipped Microsoft registration (a property set once from registration::microsoft(), so typing in the client-ID field no longer re-renders the card and loses focus). With one: helper text; a read-only monospace "Admin consent link" Field and "Open admin consent page" (reusing the open-entra callback) shown while the BYO field is empty; the BYO client-ID field inside a "Use my organization's own registration (optional)" disclosure with "Open Microsoft Entra" (new open-entra-portal callback). Without one: today's layout. - Field gains a read-only passthrough to LineEdit/TextEdit; no new component types. - on_open_entra opens the admin-consent URL only when the shared registration is active and the URL passes a gate allowing exactly the login.microsoftonline.com origin (debug-asserted); otherwise the Entra portal. shared_registration_active_for() is a pure helper with its own tests (empty / whitespace / non-empty field; no shipped id). - ADR-012: additive "Amendment (2026-10-02): shared-registration mechanism" describing build-time injection as the enablement switch while tracked configuration stays placeholder-only; no existing sentence changed. tools/check-distribution-registration- boundary.ps1: only the ADR hash literal re-pinned; P0-DIST-CROSS-CONTRACT-001 passes; the pre-existing P0-DIST-INVENTORY-001 failure is unchanged. JSON contracts untouched. - docs/native-setup.md and docs/live-connection.md describe the two modes, the "Need admin approval" screen, the unreachable localhost page after consent, and the three build-time variables (source builds without them stay BYO-only). Verified: cargo fmt --check; clippy -D warnings (desktop native-ui,ui-screenshot); desktop 438 passed, 0 failed, 3 ignored; distribution checker as above; Cargo.lock unchanged; public-repo gate on staged files. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YCesN8ZHnhqa6n3rWFThas
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Third slice of PR-1 in
docs/plans/2026-09-27-google-provider-and-shared-registration.md, on top of #59: the Sources screen's shared-registration mode, the admin-consent link, the ADR-012 amendment, and the user docs.Contract edit for owner review:
docs/adr/ADR-012-distribution-and-registration.mdgains an additive amendment (no existing sentence changed) recording build-time injection (OPENLOOPS_MS_CLIENT_ID,OPENLOOPS_GOOGLE_CLIENT_ID,OPENLOOPS_GOOGLE_CLIENT_SECRETviaoption_env!) as the enablement switch for the shared registration, while tracked configuration stays placeholder-only and every source build stays BYO-only. The JSON contracts and capability states are untouched (the evidence, protected-state and governance checkers pin every capability asdisabled). The only checker change is the ADR hash literal.UI
Fieldgains aread-onlypassthrough; no new component types.Verification
cargo fmt --all -- --check, clippy-D warnings(native-ui,ui-screenshot): cleancargo test -p openloops-desktop --features native-ui -- --test-threads=1: 438 passed, 0 failed, 3 ignoredtools/check-distribution-registration-boundary.ps1:P0-DIST-CROSS-CONTRACT-001passes with the re-pinned hash; only the pre-existingP0-DIST-INVENTORY-001(product-spec/plan/traceability hash drift from earlier PRs) fails, as onmain.Cargo.lockunchanged; public-repo gate passed on the staged files.Owner actions (free, outside the code)
Publisher verification: Partner Center account in the Microsoft AI Cloud Partner Program, DNS-verified custom domain as the registration's publisher domain, Partner One ID entered on the registration, a second registration owner. Release builds then set
OPENLOOPS_MS_CLIENT_ID. Until then the app behaves exactly as today.🤖 Generated with Claude Code
https://claude.ai/code/session_01YCesN8ZHnhqa6n3rWFThas