GitHub Authorization
GITHUB_AUTH_MODE supports:
-
installation: no user connection is required; the GitHub App installation supplies a short-lived token. -
delegated:/knowledge connectis required and the user’s push permission is checked. -
hybrid: uses delegated credentials when present; if absent, installation fallback occurs only whenGITHUB_HYBRID_INSTALLATION_FALLBACK=true.
Every mode first requires a non-empty KB_ALLOWED_REPOS match (exact owner/repo or configured owner wildcard). An empty allowlist denies every repository. Delegated access and refresh tokens are authenticated-encrypted before SQLite or memory storage. OAuth state is random, hashed at rest, expires after OAUTH_STATE_TTL_SECONDS, binds the Slack user and response URL, and is consumed once.
A draft’s creator is also its only permitted approver/editor/canceller. Human approval is mandatory before GitHub is called. See Connect GitHub.