69 lines
4.2 KiB
Markdown
69 lines
4.2 KiB
Markdown
## ADDED Requirements
|
|
|
|
### Requirement: Managed repository search is authenticated
|
|
The system SHALL authenticate every standard and recent DockerHub repository-search request through the configured DockerHub account pool using a Hub bearer token.
|
|
|
|
#### Scenario: Configured account performs search
|
|
- **WHEN** a managed DockerHub source cycle searches for repositories with an available account
|
|
- **THEN** the system sends the search request with that account's bearer authorization and records success under the `hub_search` endpoint identity
|
|
|
|
#### Scenario: Explicit pool has no usable account
|
|
- **WHEN** an explicit DockerHub account pool is configured but no account can authenticate or leave cooldown
|
|
- **THEN** the system fails the repository search without making an anonymous fallback request
|
|
|
|
#### Scenario: Search authorization is rejected
|
|
- **WHEN** a search request receives an account-specific 401, 403, or 429 response
|
|
- **THEN** the system refreshes a rejected bearer once where applicable and rotates to another usable account within the configured pool
|
|
|
|
### Requirement: Authenticated pagination is bounded
|
|
The system SHALL support up to 30 DockerHub search pages per query and SHALL cap larger requested page counts at 30.
|
|
|
|
#### Scenario: Thirty-page authenticated search
|
|
- **WHEN** a query requests 30 pages and the first page reports at least 30 pages of results
|
|
- **THEN** the system requests the complete page range from 1 through 30
|
|
|
|
#### Scenario: Request exceeds safety cap
|
|
- **WHEN** a query requests more than 30 pages
|
|
- **THEN** the system limits the search to pages 1 through 30 and records that the requested range was capped
|
|
|
|
#### Scenario: Reported result set is shorter
|
|
- **WHEN** page one reports fewer results than the requested page range would contain
|
|
- **THEN** the system requests only the pages required by that reported count
|
|
|
|
### Requirement: Page acquisition is bounded and complete
|
|
The system SHALL give each expected search page at most two transient transport/server attempts and SHALL not return partial repository results when any expected page remains unavailable.
|
|
|
|
#### Scenario: Transient failure recovers
|
|
- **WHEN** an expected page receives a retryable transport error or transient HTTP status on its first attempt and succeeds on its second attempt
|
|
- **THEN** the system includes that page and completes discovery without another transient attempt
|
|
|
|
#### Scenario: Expected page remains unavailable
|
|
- **WHEN** an expected page still fails after bounded retry and account handling
|
|
- **THEN** the system raises a DockerHub discovery transport failure before tag resolution or repository enqueue
|
|
|
|
#### Scenario: Every expected page succeeds
|
|
- **WHEN** all expected pages return valid payloads
|
|
- **THEN** the system combines their repositories in page order and proceeds with existing deduplication and resolution behavior
|
|
|
|
### Requirement: Failed pagination preserves query rotation
|
|
The system SHALL record incomplete DockerHub pagination as a failed source cycle and SHALL keep the current query cursor unchanged.
|
|
|
|
#### Scenario: Source cycle receives pagination failure
|
|
- **WHEN** repository discovery raises a DockerHub discovery transport failure
|
|
- **THEN** the source cycle finishes with failed status, enqueues no partial search result, and selects the same query for the next cycle
|
|
|
|
#### Scenario: Complete source cycle succeeds
|
|
- **WHEN** repository discovery and the remaining source cycle complete normally
|
|
- **THEN** the existing query-advance policy remains unchanged
|
|
|
|
### Requirement: Search authentication is secret-safe and isolated
|
|
The system MUST NOT expose account credentials or bearer tokens through search logs, errors, or auth events, and SHALL preserve existing tag, Registry, immutable-digest, and scan-retry behavior.
|
|
|
|
#### Scenario: Search request fails
|
|
- **WHEN** an authenticated search request fails or exhausts the account pool
|
|
- **THEN** emitted diagnostics identify only the safe endpoint/status category without including usernames, credentials, bearer values, or request authorization headers
|
|
|
|
#### Scenario: Repository search implementation changes
|
|
- **WHEN** authenticated search pagination is deployed
|
|
- **THEN** existing DockerHub tag resolution, Registry authentication, target deduplication, and scan retry contracts remain unchanged
|