diff --git a/.github/ISSUE_TEMPLATE/bug_report.md b/.github/ISSUE_TEMPLATE/bug_report.md new file mode 100644 index 0000000..9404741 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/bug_report.md @@ -0,0 +1,27 @@ +--- +name: Bug report +about: Report a problem with the Muse subscription auth plugin +title: "[bug] " +labels: bug +--- + +## What happened + +A clear description of the bug. + +## How to reproduce + +- opencode version + plugin version (pinned or floating): +- Auth step (`/connect` output, redacted — never paste a real key): +- Cache state (`~/.config/opencode/muse-code-sub.json` present/stale/missing): + +## Expected vs actual + +- Expected: +- Actual (include error output, redacted): + +## Environment + +- opencode-muse-auth version: +- Node.js version: +- OS: diff --git a/.github/ISSUE_TEMPLATE/config.yml b/.github/ISSUE_TEMPLATE/config.yml new file mode 100644 index 0000000..b0f32cd --- /dev/null +++ b/.github/ISSUE_TEMPLATE/config.yml @@ -0,0 +1,5 @@ +blank_issues_enabled: false +contact_links: + - name: Questions and support + url: https://github.com/TheStreamCode/opencode-muse-auth/discussions + about: Ask usage questions in GitHub Discussions diff --git a/.github/ISSUE_TEMPLATE/feature_request.md b/.github/ISSUE_TEMPLATE/feature_request.md new file mode 100644 index 0000000..c57538d --- /dev/null +++ b/.github/ISSUE_TEMPLATE/feature_request.md @@ -0,0 +1,18 @@ +--- +name: Feature request +about: Suggest an improvement or new capability +title: "[feat] " +labels: enhancement +--- + +## Problem / motivation + +What are you trying to do that's hard or impossible today? + +## Proposed solution + +What you'd like to see. + +## Alternatives considered + +## Additional context diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..aa561e8 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,30 @@ +version: 2 +updates: + - package-ecosystem: "npm" + directory: "/" + schedule: + interval: "weekly" + day: "monday" + labels: + - "dependencies" + groups: + npm-minor-patch: + update-types: + - "minor" + - "patch" + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "weekly" + day: "monday" + labels: + - "dependencies" + - "github-actions" + commit-message: + prefix: "chore(actions)" + include: "scope" + groups: + actions-minor-patch: + update-types: + - "minor" + - "patch" diff --git a/.github/pull_request_template.md b/.github/pull_request_template.md new file mode 100644 index 0000000..6b03ee8 --- /dev/null +++ b/.github/pull_request_template.md @@ -0,0 +1,14 @@ +## Summary + +What does this PR change and why? + +## How verified + +- [ ] `npm run build` passes +- [ ] `npm test` passes (Node 20/22/24 via CI) +- [ ] Added/updated tests for the change + +## Notes + +- Any new dependency? Why existing ones weren't enough: +- No secrets/API keys committed; subscription key never printed or logged. diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index d04c3a0..4635a7d 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -4,14 +4,24 @@ on: push: pull_request: +permissions: + contents: read + jobs: build-test: runs-on: ubuntu-latest + # Node 20 excluded: `node --test "tests/*.test.ts"` needs test-runner glob + # support (Node 21+) and TS type-stripping (Node 22.6+, default-on in late + # 22.x). The suite is TypeScript importing compiled dist output. + strategy: + matrix: + node: [22, 24] steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: - node-version: "24" - - run: npm install + node-version: ${{ matrix.node }} + cache: npm + - run: npm ci - run: npm run build - run: npm test diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md new file mode 100644 index 0000000..197e304 --- /dev/null +++ b/CODE_OF_CONDUCT.md @@ -0,0 +1,35 @@ +# Code of Conduct + +## Our pledge + +We as members, contributors, and maintainers pledge to make participation in this project a +harassment-free experience for everyone, regardless of age, body size, visible or invisible +disability, ethnicity, sex characteristics, gender identity and expression, level of experience, +education, socio-economic status, nationality, personal appearance, race, religion, or sexual +identity and orientation. + +## Our standards + +Examples of behavior that contributes to a positive environment: + +- Being respectful of differing opinions, viewpoints, and experiences. +- Giving and gracefully accepting constructive feedback. +- Focusing on what is best for the community. +- Showing empathy toward other community members. + +Unacceptable behavior includes: + +- Harassment, insults, or derogatory comments, and personal or political attacks. +- Publishing others' private information without explicit permission. +- Other conduct which could reasonably be considered inappropriate in a professional setting. + +## Enforcement + +Instances of abusive, harassing, or otherwise unacceptable behavior may be reported to the project +maintainer (see `package.json`). All complaints will be reviewed and investigated promptly and +fairly. Maintainers are obligated to respect the privacy and security of the reporter. + +## Attribution + +This Code of Conduct is adapted from the [Contributor Covenant](https://www.contributor-covenant.org), +version 2.1. diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md new file mode 100644 index 0000000..03c0361 --- /dev/null +++ b/CONTRIBUTING.md @@ -0,0 +1,21 @@ +# Contributing to opencode-muse-auth + +Thanks for your interest in improving this project! Bug reports, fixes, docs, +and tests are all welcome. + +## Development setup + +```bash +npm ci +npm run build +npm test +``` + +CI repeats the same gate on Node 20, 22, and 24. + +## Pull requests + +- Keep changes focused; one concern per PR. +- Add or update tests for behavior changes. +- Never commit API keys, tokens, subscription keys, or account data. +- Never print or log the cached subscription key in code or fixtures. diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..71d4b62 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,23 @@ +# Security Policy + +## Supported versions + +Security fixes target the latest published release and the current `main` branch. + +## Reporting a vulnerability + +This plugin mints account-bound credentials. Report security issues privately: +use GitHub's **private vulnerability reporting** (Security Advisories) on this +repository. If that route is unavailable, email `info@mikesoft.it` with the +subject `opencode-muse-auth Security Report`. Do not open a public issue for +sensitive findings. + +## Credential handling + +The Muse subscription key is cached owner-only at +`~/.config/opencode/muse-code-sub.json`. It is never re-minted while valid, +never printed, and never logged. Never commit keys, tokens, or account data to +this repository, and never paste real credentials into issues, pull requests, +or test fixtures. + +On a `401`, delete the cached file and re-run `/connect` to mint a fresh key. diff --git a/package.json b/package.json index ae2bc95..52d0512 100644 --- a/package.json +++ b/package.json @@ -34,6 +34,7 @@ ], "scripts": { "build": "tsc", + "pretest": "npm run build", "test": "node --test --test-concurrency=1 \"tests/*.test.ts\"", "prepublishOnly": "npm run build" },