Two main fixes here, if you're accepting them:
- Auth was hard-coded to Bluesky PDS's. This lets someone on a non-Bluesky PDS log in, and it does so without specifying a flag by just looking up their DID doc
- Let people access issues in a repo they don't own. The former assumption was that the logged in user also owned the repo, which isn't always true
Co-authored-by: Claude (claude-sonnet-4-6) noreply@anthropic.com