Update skill

Seto Elkahfi committed Jun 17, 2026 at 16:52 UTC 729d5cd7b25fc52945c05568ddfa573524be6f86
1 file changed +38
.agents/skills/sigit-app/SKILL.md
+38
@@ -78,6 +78,40 @@ If switching to the API path, change the command bodies to call
78 `sigit.si/api/v1/*` and keep the **same** `AccountStatus` / `ErrorResponse`
79 shapes so the frontend and token storage are unaffected.
80
81 +## Git operations (repos)
82 +
83 +Git uses **Smart HTTP with token auth — no SSH.** Live commands in
84 +`src-tauri/src/repos/` (registered in `lib.rs`):
85 +
86 +- `clone_repo` · `publish_repo` · `push_repo` / `pull_repo` · `list_repos`
87 +
88 +Two-token flow — **never use the account access token as a git credential**:
89 +
90 +1. login → **account access token** persisted via `crate::store::store_token`
91 +2. `repos::api::fetch_git_token(env, access_token)` POSTs `sigit.si` →
92 + `git_credentials` (bearer = access token) → returns a **short-lived scoped
93 + `git_token`**
94 +3. git2 credential callback authenticates over HTTPS via HTTP Basic:
95 + `Cred::userpass_plaintext("x-access-token", git_token)` — username is the
96 + literal string `x-access-token`, password is the scoped git token
97 +4. `repos::api::create_remote_repo` POSTs `repos` (bearer = access token) to
98 + create the bare repo before first publish
99 +
100 +This is in-process libgit2 (`git2` / `gix`, vendored) over HTTPS — no subprocess,
101 +no key files — so it works inside the **sandboxed App Store build** and the
102 +container-stored-repo model.
103 +
104 +### Legacy SSH path (deprecated — do not extend)
105 +
106 +`src/_git/{clone_project,desktop_deploy}.rs`,
107 +`src/project/command_clone_frontend_app.rs`, and
108 +`src/ssh/command_generate_ssh_key.rs` still use `Cred::ssh_key` and remain
109 +registered (`clone_project`, `clone_frontend_app`, `ssh_clone`,
110 +`generate_ssh_key`), but SSH-based git is **no longer the model** — new work uses
111 +the Smart HTTP path above. `desktop_deploy.rs` also hardcodes
112 +`/Users/setoelkahfi/.ssh/...`, which is dead in any non-author or sandboxed
113 +build. Candidates for removal, not extension.
114 +
115 ## Validation
116
117 - `cargo check` in `src-tauri`
@@ -93,3 +127,7 @@ shapes so the frontend and token storage are unaffected.
127 - Treating the Anthropic API key field as an auth credential — it is local-only
128 - Shipping smbCloud `app_secret` in the binary and assuming it is confidential
129 - Diverging account features from the sigit-si web account page
130 +- Reaching for SSH credentials / `generate_ssh_key` for git auth — the live path
131 + is Smart HTTP over HTTPS (`repos::*`), not `Cred::ssh_key`
132 +- Using the account access token directly as the git credential — always
133 + exchange it for a short-lived scoped `git_token` via `fetch_git_token` first