Skip to content

Commit a78801a

Browse files
committed
feat(rhodibot): GitHub App authentication and a GraphQL client
rhodibot could not act as a GitHub App: the only credential it understood was a single-repository GITHUB_TOKEN. This adds the RS256 JWT signing, the installation-token exchange and cache, and a GraphQL client for the check runs and issues the bot writes. ring and base64 are taken at versions already in Cargo.lock, so the dependency graph gains no new packages - which matters because CI builds with --locked. Verified locally with rustc 1.98.1: fmt clean, clippy -D warnings clean, 95 tests pass, including 12 new wiremock tests covering the handshake, token caching and refresh, and the GraphQL error paths.
1 parent 0ab0fd1 commit a78801a

6 files changed

Lines changed: 1231 additions & 8 deletions

File tree

‎bots/rhodibot/Cargo.lock‎

Lines changed: 2 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎bots/rhodibot/Cargo.toml‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,15 @@ serde = { version = "1.0.228", features = ["derive"] }
3030
serde_json = "1.0.150"
3131
toml = "1.1.2+spec-1.1.0"
3232

33+
# Crypto for GitHub App JWT signing (RS256).
34+
#
35+
# `ring` and `base64` are deliberately taken from versions already present in
36+
# Cargo.lock via rustls/reqwest, so this adds no new package to the graph --
37+
# which matters because CI builds with `--locked` and a regenerated lock would
38+
# otherwise have to be trusted sight-unseen.
39+
ring = "0.17"
40+
base64 = "0.22"
41+
3342
# Crypto for webhook verification
3443
hmac = "0.13.0"
3544
sha2 = "0.11.0"

0 commit comments

Comments
 (0)