diff --git a/docs/development.md b/docs/development.md index 761d9d5..4b04eeb 100644 --- a/docs/development.md +++ b/docs/development.md @@ -217,7 +217,7 @@ and local CLI operations evolve independently: Security rules for the package: - Credential models store **only** `encrypted_payload` — no plaintext `token` or `private_key` fields. - SSH private keys are encrypted before storage; the field uses `repr=False`. -- Real encryption of the payload is deferred to FN-009; the current placeholder is base64-only. +- SSH private keys are encrypted with Fernet before storage. ## Tool Spawn Workflow @@ -324,6 +324,59 @@ When a tool instance is spawned: Before spawning, the system validates that all required secrets exist. If any are missing, the spawn fails with an error message listing the missing secrets. +## Repository Connections + +### Overview + +The platform supports connecting Git repositories to projects with provider-independent authentication. + +### Architecture + +1. **Repository** (`apps/api/app/models/repository.py`): + - Stores repository metadata (name, git_url, provider_type, default_branch) + - Belongs to a project + +2. **Repository Connection** (`apps/api/app/models/repository_connection.py`): + - Links a repository to a Git provider with credentials + - Tracks connection status (pending, connected, error, disconnected) + - Supports SSH key authentication + +3. **Credential Storage** (`apps/api/app/git/credential_storage.py`): + - Database-backed storage for encrypted credentials + - Uses Fernet encryption for payload + - Supports access tokens and SSH keys + +4. **Provider Adapters** (`apps/api/app/git/providers/`): + - GitHubAdapter and GitLabAdapter with URL parsing + - Extensible for other providers (Gitea, Forgejo) + +5. **SSH Key Lifecycle** (`apps/api/app/git/ssh_key.py`): + - Ed25519 key pair generation + - Fernet-encrypted private key storage + - Public key available for deploy key registration + +### API Endpoints + +- `POST /projects/{id}/repositories` — Add repository +- `GET /projects/{id}/repositories` — List repositories +- `DELETE /projects/{id}/repositories/{id}` — Remove repository +- `POST /projects/{id}/repository-connections` — Create connection +- `GET /projects/{id}/repository-connections` — List connections +- `DELETE /projects/{id}/repository-connections/{id}` — Remove connection +- `POST /projects/{id}/repository-connections/{id}/ssh-key` — Generate SSH key +- `POST /projects/{id}/repository-connections/{id}/validate` — Validate connection + +### Frontend + +- `/repositories` — Repository list and creation +- `/projects/{id}/repositories/{id}` — Repository detail with connections + +### Git Operations + +Local Git operations are supported via subprocess: +- Clone, fetch, push with credential-aware subprocess +- Working tree status (branch, clean, untracked, modified, staged, deleted) + ## OpenCode Tool ### Overview