refactor: split request auth from local owner lookup #365
Labels
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
status:blocked
track:api
track:auto
track:core
track:deploy
track:infra
track:ui
type:cleanup
type:docs
type:epic
type:release
type:research
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
barrettruth/delta#365
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Parent: #355
Problem
Auth helpers mix local owner creation/lookup, API-key request auth, unauthorized responses, and IP/rate-limit utilities. Some routes intentionally use local owner access while others require request auth, but helper names do not make that boundary obvious.
Solution
Split the auth helper surface by responsibility:
Acceptance criteria