mirror of
https://github.com/superdesigndev/treg.git
synced 2026-10-02 03:24:35 +08:00
The add-on signs in with treg's own OAuth server (authorization code + PKCE S256, public client). - Client `treg-sheets`, scope `treg:table`, resource `<public_url>/table`. Not a table row: built from TREG_SHEETS_REDIRECT_URIS (exact match, one per Apps Script project), and only while the table flag is on. It gets that resource and nothing else, and no other client may ask for it, so an MCP token never works on the table routes and this token never works on MCP. - The token works only on /table/*, /table-columns/* and the new GET /table-account. table_caller checks the audience and presents the person to require_member as a two-minute identity, the way MCP exchanges its own token. Every other route still ignores a Bearer header. The Authorization header is removed before the call, so treg's token never reaches a provider. - The grant belongs to the person, not one team (owner decision): the consent page has no team picker, the token carries a default team, and each request picks one with X-Treg-Org, checked for membership and role every time. A refresh whose default team the person left moves the default to another of their teams; only leaving every team ends the grant. - GET /table-account: email, active team, and the teams with role and balance (every team with this token; the key's one team with a team key). - Consent page text from the owner's mockup. Also: a one-item list under a wrapper name (`data`, `results`...) was opened as a wrapper even when it held no tables, so a search that found one record showed one JSON cell. It is now one row. Tests: tests/test_table_oauth.py (consent page, one sign-in reaches every team, a team the person is not in is refused, the token works nowhere else, an MCP token does not work here, only this client gets the resource, no setting means no client, refresh and sign-out) and one converter test. Updates docs/context/architecture/table.md and mcp-oauth.md.