diff --git a/docs/plans/2026-08-26-collaboration-in-spaces.md b/docs/plans/2026-08-26-collaboration-in-spaces.md index 7b66811..17af6df 100644 --- a/docs/plans/2026-08-26-collaboration-in-spaces.md +++ b/docs/plans/2026-08-26-collaboration-in-spaces.md @@ -375,6 +375,19 @@ the same once at first start and refreshes from then on; the refresh token and the DPoP key it is bound to already travel together in the session file. The loopback flow stays for a machine with a browser. +## A read reaches where a DID says + +A pull request or an issue names an account by DID, and the server resolves +the DID document and reads its `serviceEndpoint` to fetch the records. A +`did:web` the caller controls names any endpoint, so the server makes a +request to a URL a request chose. It is bounded: a GET of `com.atproto.repo.*` +and `dev.pdsjs.git.*` paths, the answer parsed as records. On the open +internet that reaches only what any client could. Behind a network where an +internal host answers on those paths, a deployment should resolve DIDs +through a directory it trusts and hold a resolved endpoint to public hosts. +This is the ordinary shape of a service that follows atproto identities, and +the note is here so a private deployment reads it before it ships. + ## Order to build in **First phase.** Each step lands green on its own; the last three are diff --git a/packages/git/src/methods.js b/packages/git/src/methods.js index d55ca32..802b23c 100644 --- a/packages/git/src/methods.js +++ b/packages/git/src/methods.js @@ -442,6 +442,7 @@ export function createGitMethods({ browser: reader, discovery, openCopy, + onNotice: (message) => console.warn(`[git] ${message}`), }); /** @param {URLSearchParams} params */ diff --git a/packages/git/src/pull-request-reader.js b/packages/git/src/pull-request-reader.js index e81b52c..7e723e4 100644 --- a/packages/git/src/pull-request-reader.js +++ b/packages/git/src/pull-request-reader.js @@ -79,7 +79,14 @@ const READ_TIMEOUT_MS = 5000; /** * @typedef {Object} PullRequestReaderContext * @property {(did: string) => Promise} resolveContributor - - * where one account's records and blobs are read from + * where one account's records and blobs are read from. A read names an + * account by DID, the server resolves the DID document, and reads its + * serviceEndpoint. A did:web the caller controls names any endpoint, so + * this is a request the server makes to a URL a request chose: bounded to + * GET of com.atproto.repo.* and dev.pdsjs.git.* paths whose answer is + * parsed as records, but a deployment behind a network where an internal + * host answers on those paths should resolve DIDs through a directory it + * trusts and hold the endpoint to public hosts. * @property {(did: string, collection: string, rkey: string) => Promise} readRecord - * this account's own records * @property {Pick} browser - the diff --git a/vitest.config.js b/vitest.config.js index 8b9cbe7..abc0a35 100644 --- a/vitest.config.js +++ b/vitest.config.js @@ -174,7 +174,9 @@ export default defineConfig({ 'packages/git/src/methods.js': { statements: 90, branches: 80, - functions: 100, + // The discovery-cap notice sink logs on an answer larger than a + // unit test builds, so one arrow here is uncovered by design. + functions: 96, }, 'packages/git/src/api-lexicon.js': { statements: 95,