## ADDED Requirements ### Requirement: Managed repository search is authenticated The system SHALL authenticate every standard and recent DockerHub repository-search request through the configured DockerHub account pool using a Hub bearer token. #### Scenario: Configured account performs search - **WHEN** a managed DockerHub source cycle searches for repositories with an available account - **THEN** the system sends the search request with that account's bearer authorization and records success under the `hub_search` endpoint identity #### Scenario: Explicit pool has no usable account - **WHEN** an explicit DockerHub account pool is configured but no account can authenticate or leave cooldown - **THEN** the system fails the repository search without making an anonymous fallback request #### Scenario: Search authorization is rejected - **WHEN** a search request receives an account-specific 401, 403, or 429 response - **THEN** the system refreshes a rejected bearer once where applicable and rotates to another usable account within the configured pool ### Requirement: Authenticated pagination is bounded The system SHALL support up to 30 DockerHub search pages per query and SHALL cap larger requested page counts at 30. #### Scenario: Thirty-page authenticated search - **WHEN** a query requests 30 pages and the first page reports at least 30 pages of results - **THEN** the system requests the complete page range from 1 through 30 #### Scenario: Request exceeds safety cap - **WHEN** a query requests more than 30 pages - **THEN** the system limits the search to pages 1 through 30 and records that the requested range was capped #### Scenario: Reported result set is shorter - **WHEN** page one reports fewer results than the requested page range would contain - **THEN** the system requests only the pages required by that reported count ### Requirement: Page acquisition is bounded and complete The system SHALL give each expected search page at most two transient transport/server attempts and SHALL not return partial repository results when any expected page remains unavailable. #### Scenario: Transient failure recovers - **WHEN** an expected page receives a retryable transport error or transient HTTP status on its first attempt and succeeds on its second attempt - **THEN** the system includes that page and completes discovery without another transient attempt #### Scenario: Expected page remains unavailable - **WHEN** an expected page still fails after bounded retry and account handling - **THEN** the system raises a DockerHub discovery transport failure before tag resolution or repository enqueue #### Scenario: Every expected page succeeds - **WHEN** all expected pages return valid payloads - **THEN** the system combines their repositories in page order and proceeds with existing deduplication and resolution behavior ### Requirement: Failed pagination preserves query rotation The system SHALL record incomplete DockerHub pagination as a failed source cycle and SHALL keep the current query cursor unchanged. #### Scenario: Source cycle receives pagination failure - **WHEN** repository discovery raises a DockerHub discovery transport failure - **THEN** the source cycle finishes with failed status, enqueues no partial search result, and selects the same query for the next cycle #### Scenario: Complete source cycle succeeds - **WHEN** repository discovery and the remaining source cycle complete normally - **THEN** the existing query-advance policy remains unchanged ### Requirement: Search authentication is secret-safe and isolated The system MUST NOT expose account credentials or bearer tokens through search logs, errors, or auth events, and SHALL preserve existing tag, Registry, immutable-digest, and scan-retry behavior. #### Scenario: Search request fails - **WHEN** an authenticated search request fails or exhausts the account pool - **THEN** emitted diagnostics identify only the safe endpoint/status category without including usernames, credentials, bearer values, or request authorization headers #### Scenario: Repository search implementation changes - **WHEN** authenticated search pagination is deployed - **THEN** existing DockerHub tag resolution, Registry authentication, target deduplication, and scan retry contracts remain unchanged