Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove ALL existing code related to stored sponsors #57

Merged
merged 1 commit into from
Aug 23, 2023
Merged

Conversation

kzu
Copy link
Member

@kzu kzu commented Aug 23, 2023

Since we're moving to an entirely offline and manifest-based SL check, we don't need any of the complex stuff we had before. We just need a SINGLE endpoint to sign the JWT manifest sent by the gh-sponsors extension (see devlooped/gh-sponsors#8). Everything else is unnecessary now.

The functionality is reduced but simplified significantly, with a massive improvement in PII/GDPR compliance. There is no longer any direct nor indirect telemetry tracked since the user must explicitly run a command and install an extension in their machine before getting a signed manifest.

We also no longer provide a webhook for the GH apps, which will be deprecated too.

Fixes #31

Since we're moving to an entirely offline and manifest-based SL check, we don't need any of the complex stuff we had before. We just need a SINGLE endpoint to sign the JWT manifest sent by the gh-sponsors extension (see devlooped/gh-sponsors#8). Everything else is unnecessary now.

The functionality is reduced but simplified significantly, with a massive improvement in PII/GDPR compliance. There is no longer any direct nor indirect telemetry tracked since the user must explicitly run a command and install an extension in their machine before getting a signed manifest.

We also no longer provide a webhook for the GH apps, which will be deprecated too.

Fixes #31
@kzu kzu enabled auto-merge (rebase) August 23, 2023 16:47
@kzu kzu merged commit 6e3c311 into main Aug 23, 2023
@kzu kzu deleted the dev/manifest branch August 23, 2023 16:50
This was referenced Aug 25, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Replace hashed email with manifest-based offline check
1 participant