Files
2026-09-30 20:30:56 +03:00

4.2 KiB

ADDED Requirements

Requirement: Managed repository search is authenticated

The system SHALL authenticate every standard and recent DockerHub repository-search request through the configured DockerHub account pool using a Hub bearer token.

  • WHEN a managed DockerHub source cycle searches for repositories with an available account
  • THEN the system sends the search request with that account's bearer authorization and records success under the hub_search endpoint identity

Scenario: Explicit pool has no usable account

  • WHEN an explicit DockerHub account pool is configured but no account can authenticate or leave cooldown
  • THEN the system fails the repository search without making an anonymous fallback request

Scenario: Search authorization is rejected

  • WHEN a search request receives an account-specific 401, 403, or 429 response
  • THEN the system refreshes a rejected bearer once where applicable and rotates to another usable account within the configured pool

Requirement: Authenticated pagination is bounded

The system SHALL support up to 30 DockerHub search pages per query and SHALL cap larger requested page counts at 30.

  • WHEN a query requests 30 pages and the first page reports at least 30 pages of results
  • THEN the system requests the complete page range from 1 through 30

Scenario: Request exceeds safety cap

  • WHEN a query requests more than 30 pages
  • THEN the system limits the search to pages 1 through 30 and records that the requested range was capped

Scenario: Reported result set is shorter

  • WHEN page one reports fewer results than the requested page range would contain
  • THEN the system requests only the pages required by that reported count

Requirement: Page acquisition is bounded and complete

The system SHALL give each expected search page at most two transient transport/server attempts and SHALL not return partial repository results when any expected page remains unavailable.

Scenario: Transient failure recovers

  • WHEN an expected page receives a retryable transport error or transient HTTP status on its first attempt and succeeds on its second attempt
  • THEN the system includes that page and completes discovery without another transient attempt

Scenario: Expected page remains unavailable

  • WHEN an expected page still fails after bounded retry and account handling
  • THEN the system raises a DockerHub discovery transport failure before tag resolution or repository enqueue

Scenario: Every expected page succeeds

  • WHEN all expected pages return valid payloads
  • THEN the system combines their repositories in page order and proceeds with existing deduplication and resolution behavior

Requirement: Failed pagination preserves query rotation

The system SHALL record incomplete DockerHub pagination as a failed source cycle and SHALL keep the current query cursor unchanged.

Scenario: Source cycle receives pagination failure

  • WHEN repository discovery raises a DockerHub discovery transport failure
  • THEN the source cycle finishes with failed status, enqueues no partial search result, and selects the same query for the next cycle

Scenario: Complete source cycle succeeds

  • WHEN repository discovery and the remaining source cycle complete normally
  • THEN the existing query-advance policy remains unchanged

Requirement: Search authentication is secret-safe and isolated

The system MUST NOT expose account credentials or bearer tokens through search logs, errors, or auth events, and SHALL preserve existing tag, Registry, immutable-digest, and scan-retry behavior.

Scenario: Search request fails

  • WHEN an authenticated search request fails or exhausts the account pool
  • THEN emitted diagnostics identify only the safe endpoint/status category without including usernames, credentials, bearer values, or request authorization headers

Scenario: Repository search implementation changes

  • WHEN authenticated search pagination is deployed
  • THEN existing DockerHub tag resolution, Registry authentication, target deduplication, and scan retry contracts remain unchanged