Skip to content

[Plugin] zboard.oauth v0.0.1 — signed release submission #1

Description

@higanbana986

Submission / 收录申请

Please review the signed OAuth for ZBoard v0.0.1 release for the ZBoard catalog. The source-only listing already exists; this request supplies production release artifacts and publisher information. Listing approval remains with marketplace maintainers.

申请审核 OAuth for ZBoard v0.0.1 正式签名版本。已有源码条目,本次补充发行产物和发布者资料,由市场维护者审核收录。

Field / 字段 Value / 内容
Host / 宿主 zboard
Plugin ID / 插件 ID zboard.oauth
Release / 发行 v0.0.1
Source / 源码 higanbana986/zboard-oauth
Commit / 提交 6d48f3b2f19361b0abbdae1b7d24722cc466385a
Maintainer / 维护者 higanbana986
License / 许可证 MPL-2.0

Release metadata / 发行元数据

Platform / 平台 Bytes / 字节 SHA-256 Package / 安装包
linux-amd64 5491102 fb087e7fd51c7d76d634b7a43f81c5f097ba43a9b221a1d6da17aac1c52b528f Download
linux-arm64 4989973 685fcbb6c8fa967d0198341e16809c022ac86976161a42f366ddb9fa0e2e712d Download
darwin-amd64 5622952 5f22baa043528721830041432f3a3451138bb80926c056a29afad71d8b26fba3 Download
darwin-arm64 5223565 31ebde7e77441f81a23644e146ce6e2aab5b781a299ae2cdde7694d6b4704352 Download
windows-amd64 5655303 648ff13a61c60ca1fecd667978dea08ef281324426b7d594de0c2d58f3a41beb Download

Publisher / 发布者

Package key ID: higanbana986. Ed25519 public key:

k+s2/1J6/R9VSNbc2bcX3C8KRBXVZ+IrSKFButaR4Q4=

The source and signed assets are published by the maintainer's repository. The release workflow verifies the configured key pair and invokes ZBoard's packager to verify every package. Public-key ownership and trust admission should be reviewed independently; inclusion of this key is not a request to bypass host trust configuration. No private key is included.

源码及签名包由维护者仓库发行。工作流核对公私钥匹配,并调用 ZBoard 打包工具对每个包验签。公钥归属与信任准入仍须独立审核,不绕过宿主信任配置;申请不含私钥。

Compatibility and permissions / 兼容性与权限

  • Requires ZBoard >=0.0.1 <0.1.0, plugin protocol 1 and UI bridge 1. The host must implement the multi-provider identity API; a version string alone is insufficient. The workflow uses the pinned host packager at 96607bd84893be6fc355b5ebe12ff60b9eac86be.
  • Capabilities: zboard.ui.page.v1, zboard.config.v1, zboard.identity.provider.v1.
  • UI surface: admin, for provider configuration. GitHub, Google and custom OAuth2/OIDC providers integrate with the core login flow.
  • ZBoard owns accounts, identity bindings, registration restrictions, account status and sessions. The plugin does not create core tables or perform arbitrary SQL. Configuration, private storage, migrations and uninstall retention remain host-controlled; existing core accounts and bindings are not deleted by uninstalling this plugin.

需支持多提供方身份 API 的 ZBoard 宿主。管理员页面只负责提供方配置;账户、关联身份、注册限制及会话由核心掌管。插件不自行建核心表或执行任意 SQL,配置、迁移及卸载保留策略由宿主管理。

Validation and operating limits / 验证与运行限制

  • Go race tests, vet, process integration tests, UI tests and release metadata tests pass in CI.
  • Five platform packages are cross-compiled and verified by the host packager with the production publisher key.
  • All five GitHub-recorded asset SHA-256 digests and byte sizes match SHA256SUMS and marketplace metadata. The release public key matches the maintainer's local public key. The downloaded darwin-arm64 package was independently checked locally for its SHA-256, Ed25519 signature and every manifest file digest. Downloads of other targets encountered timeouts; local verification of those downloads is not claimed.
  • Native execution on all target platforms, live third-party login, and macOS signing/notarization are not claimed by these checks.
  • Current ZBoard online downloads reject redirects. GitHub Release URLs therefore require offline import or a compatible direct-download mirror until the host supports those redirects. Source registry JSON is not a signed installation feed.

CI 与本地产物核验不替代各平台原生运行、真实提供方登录或 macOS 签名公证验收。当前 ZBoard 在线下载不接受重定向,因此这些 Release 包可先离线导入;在线接入仍需兼容的直连镜像或宿主下载能力调整。

Security reporting · Configuration guide

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

host:zboardZBoard plugin / 面板插件plugin:submissionPlugin marketplace admission / 插件市场入驻申请status:acceptedPlugin admitted to the marketplace / 插件已通过市场准入

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions