4.2 KiB
ADDED Requirements
Requirement: Managed repository search is authenticated
The system SHALL authenticate every standard and recent DockerHub repository-search request through the configured DockerHub account pool using a Hub bearer token.
Scenario: Configured account performs search
- WHEN a managed DockerHub source cycle searches for repositories with an available account
- THEN the system sends the search request with that account's bearer authorization and records success under the
hub_searchendpoint identity
Scenario: Explicit pool has no usable account
- WHEN an explicit DockerHub account pool is configured but no account can authenticate or leave cooldown
- THEN the system fails the repository search without making an anonymous fallback request
Scenario: Search authorization is rejected
- WHEN a search request receives an account-specific 401, 403, or 429 response
- THEN the system refreshes a rejected bearer once where applicable and rotates to another usable account within the configured pool
Requirement: Authenticated pagination is bounded
The system SHALL support up to 30 DockerHub search pages per query and SHALL cap larger requested page counts at 30.
Scenario: Thirty-page authenticated search
- WHEN a query requests 30 pages and the first page reports at least 30 pages of results
- THEN the system requests the complete page range from 1 through 30
Scenario: Request exceeds safety cap
- WHEN a query requests more than 30 pages
- THEN the system limits the search to pages 1 through 30 and records that the requested range was capped
Scenario: Reported result set is shorter
- WHEN page one reports fewer results than the requested page range would contain
- THEN the system requests only the pages required by that reported count
Requirement: Page acquisition is bounded and complete
The system SHALL give each expected search page at most two transient transport/server attempts and SHALL not return partial repository results when any expected page remains unavailable.
Scenario: Transient failure recovers
- WHEN an expected page receives a retryable transport error or transient HTTP status on its first attempt and succeeds on its second attempt
- THEN the system includes that page and completes discovery without another transient attempt
Scenario: Expected page remains unavailable
- WHEN an expected page still fails after bounded retry and account handling
- THEN the system raises a DockerHub discovery transport failure before tag resolution or repository enqueue
Scenario: Every expected page succeeds
- WHEN all expected pages return valid payloads
- THEN the system combines their repositories in page order and proceeds with existing deduplication and resolution behavior
Requirement: Failed pagination preserves query rotation
The system SHALL record incomplete DockerHub pagination as a failed source cycle and SHALL keep the current query cursor unchanged.
Scenario: Source cycle receives pagination failure
- WHEN repository discovery raises a DockerHub discovery transport failure
- THEN the source cycle finishes with failed status, enqueues no partial search result, and selects the same query for the next cycle
Scenario: Complete source cycle succeeds
- WHEN repository discovery and the remaining source cycle complete normally
- THEN the existing query-advance policy remains unchanged
Requirement: Search authentication is secret-safe and isolated
The system MUST NOT expose account credentials or bearer tokens through search logs, errors, or auth events, and SHALL preserve existing tag, Registry, immutable-digest, and scan-retry behavior.
Scenario: Search request fails
- WHEN an authenticated search request fails or exhausts the account pool
- THEN emitted diagnostics identify only the safe endpoint/status category without including usernames, credentials, bearer values, or request authorization headers
Scenario: Repository search implementation changes
- WHEN authenticated search pagination is deployed
- THEN existing DockerHub tag resolution, Registry authentication, target deduplication, and scan retry contracts remain unchanged