@@ -112,3 +112,35 @@ The initial production validation confirmed:
112112- ` LibreCodeCoop/extract ` can be checked out and updated;
113113- managed workflows can be adopted into the lock file;
114114- a subsequent synchronization with current hashes creates no PR.
115+
116+
117+ ## Portable consumer authentication
118+
119+ The installed workflow updater does not infer authentication from the consumer's
120+ organization name. Consumers select an explicit repository variable:
121+
122+ \` WORKFLOW_SYNC_AUTH_MODE\`
123+
124+ Supported values:
125+
126+ - \` librecode-app\` — default for existing LibreCode-managed repositories. Uses
127+ \` LIBRECODE_WORKFLOW_APP_ID\` and \` LIBRECODE_WORKFLOW_APP_PRIVATE_KEY\` .
128+ - \` github-app\` — uses a consumer-owned GitHub App configured through
129+ \` WORKFLOW_SYNC_APP_ID\` and \` WORKFLOW_SYNC_APP_PRIVATE_KEY\` .
130+ - \` token\` — uses a consumer-owned repository-scoped credential stored as
131+ \` WORKFLOW_SYNC_TOKEN\` .
132+ - \` github-token\` — uses the workflow's built-in \` GITHUB_TOKEN\` .
133+
134+ A consumer-owned GitHub App is preferred for independent projects because it
135+ keeps credentials under the consumer's control while still allowing generated
136+ pull requests to trigger normal repository automation.
137+
138+ The \` github-token\` mode is intentionally explicit. GitHub suppresses workflow
139+ runs caused by most events created with the repository \` GITHUB_TOKEN\` , which
140+ means a pull request created through that mode may not trigger the consumer's
141+ normal pull-request CI. Use it only when that limitation is acceptable or when
142+ another mechanism explicitly triggers validation.
143+
144+ For GitHub App credentials, request only the repository permissions needed by
145+ the updater: Contents write, Pull requests write and Workflows write. Do not
146+ install or share the LibreCode GitHub App/private key with external consumers.
0 commit comments