Skip to content

self-serve developer apps with collaborator invite lifecycle #100

Description

@jaspermayone

Why

OAuth apps are currently admin-managed. At Hack Club scale, third-party developers register their own apps; governance comes from scope tiers (#91), not a human approval queue.

What

  • /developer/apps self-serve surface, gated by a developer_mode user flag; Pundit-driven (adopt pundit with fail-closed policies #88).
  • Collaborators: email-based invitations that bind to a user on accept; AASM lifecycle pending → accepted / declined / cancelled / removed with reinvite; owner + collaborators share management rights per policy.
  • Credential hygiene: rotate-credentials action, bulk revoke-all-authorizations (with paper_trail version), per-app activity log.
  • Trust-tier + locked-scope enforcement from oauth app trust tiers with server-side locked-scope enforcement #91 applies to every edit.

Reference

Notes

Their hackclub/auth#186 (Program vs Developer App vs App naming confusion) — pick ONE name and use it everywhere from the start.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions