Update skill
Seto Elkahfi committed
Jun 17, 2026 at 16:52 UTC
729d5cd7b25fc52945c05568ddfa573524be6f86
1 file changed
+38
.agents/skills/sigit-app/SKILL.md
+38
@@ -78,6 +78,40 @@ If switching to the API path, change the command bodies to call
78
`sigit.si/api/v1/*` and keep the **same** `AccountStatus` / `ErrorResponse`
79
shapes so the frontend and token storage are unaffected.
80
81
+## Git operations (repos)
82
+
83
+Git uses **Smart HTTP with token auth — no SSH.** Live commands in
84
+`src-tauri/src/repos/` (registered in `lib.rs`):
85
+
86
+- `clone_repo` · `publish_repo` · `push_repo` / `pull_repo` · `list_repos`
87
+
88
+Two-token flow — **never use the account access token as a git credential**:
89
+
90
+1. login → **account access token** persisted via `crate::store::store_token`
91
+2. `repos::api::fetch_git_token(env, access_token)` POSTs `sigit.si` →
92
+ `git_credentials` (bearer = access token) → returns a **short-lived scoped
93
+ `git_token`**
94
+3. git2 credential callback authenticates over HTTPS via HTTP Basic:
95
+ `Cred::userpass_plaintext("x-access-token", git_token)` — username is the
96
+ literal string `x-access-token`, password is the scoped git token
97
+4. `repos::api::create_remote_repo` POSTs `repos` (bearer = access token) to
98
+ create the bare repo before first publish
99
+
100
+This is in-process libgit2 (`git2` / `gix`, vendored) over HTTPS — no subprocess,
101
+no key files — so it works inside the **sandboxed App Store build** and the
102
+container-stored-repo model.
103
+
104
+### Legacy SSH path (deprecated — do not extend)
105
+
106
+`src/_git/{clone_project,desktop_deploy}.rs`,
107
+`src/project/command_clone_frontend_app.rs`, and
108
+`src/ssh/command_generate_ssh_key.rs` still use `Cred::ssh_key` and remain
109
+registered (`clone_project`, `clone_frontend_app`, `ssh_clone`,
110
+`generate_ssh_key`), but SSH-based git is **no longer the model** — new work uses
111
+the Smart HTTP path above. `desktop_deploy.rs` also hardcodes
112
+`/Users/setoelkahfi/.ssh/...`, which is dead in any non-author or sandboxed
113
+build. Candidates for removal, not extension.
114
+
115
## Validation
116
117
- `cargo check` in `src-tauri`
@@ -93,3 +127,7 @@ shapes so the frontend and token storage are unaffected.
127
- Treating the Anthropic API key field as an auth credential — it is local-only
128
- Shipping smbCloud `app_secret` in the binary and assuming it is confidential
129
- Diverging account features from the sigit-si web account page
130
+- Reaching for SSH credentials / `generate_ssh_key` for git auth — the live path
131
+ is Smart HTTP over HTTPS (`repos::*`), not `Cred::ssh_key`
132
+- Using the account access token directly as the git credential — always
133
+ exchange it for a short-lived scoped `git_token` via `fetch_git_token` first