GitHub Authorization

GITHUB_AUTH_MODE supports:

  • installation: no user connection is required; the GitHub App installation supplies a short-lived token.

  • delegated: /knowledge connect is required and the user’s push permission is checked.

  • hybrid: uses delegated credentials when present; if absent, installation fallback occurs only when GITHUB_HYBRID_INSTALLATION_FALLBACK=true.

Every mode first requires a non-empty KB_ALLOWED_REPOS match (exact owner/repo or configured owner wildcard). An empty allowlist denies every repository. Delegated access and refresh tokens are authenticated-encrypted before SQLite or memory storage. OAuth state is random, hashed at rest, expires after OAUTH_STATE_TTL_SECONDS, binds the Slack user and response URL, and is consumed once.

A draft’s creator is also its only permitted approver/editor/canceller. Human approval is mandatory before GitHub is called. See Connect GitHub.