Skip to content

Expose authenticated GET /api/packages/<package>/publishing endpoint for configuration introspection #9559

Description

@kevmoo

Context & Problem

Currently, pub.dev only exposes PUT /api/packages/<package>/publishing (gated behind web session cookies). There is no programmatic GET endpoint to retrieve a package's publishing configuration.

This prevents:

  1. GitHub Actions & CI Pipelines: Automated workflows cannot verify whether their repository, environment, and tag patterns match the registered package configuration before attempting release or publish steps.
  2. Developer & Agent Tooling: CLI tools and AI coding assistants cannot inspect automated publishing settings, manual publishing locks, or GCP service account associations using stored credentials.

Proposed Solution

Add an authenticated GET /api/packages/<package>/publishing endpoint in pubapi.dart returning the PkgPublishingConfig payload.

Authorization Matrix

The endpoint requires a valid Bearer token (requireAuthenticatedClient()):

Caller Identity Condition for Access Unauthorized Error
User (OAuth) Caller is a package admin or publisher admin 403 Forbidden (InsufficientPermissions)
GitHub Action (OIDC) agent.payload.repository == githubConfig.repository 403 Forbidden (InsufficientPermissions)
GCP Service Account (OIDC) agent.email == gcpConfig.serviceAccountEmail 403 Forbidden (InsufficientPermissions)
Anonymous / Expired Missing or invalid Bearer token 401 Unauthorized (MissingAuthentication)

Note: For GitHub Actions OIDC introspection, only the repository identity is validated; tag pattern and environment constraints are only enforced during pub publish.

Acceptance Criteria

  • Add GET /api/packages/<package>/publishing route in pubapi.dart and pubapi.client.dart.
  • Implement packageBackend.getPackagePublishing(String package) with authorization checks for User admins, GitHub Actions OIDC tokens, and GCP Service Accounts.
  • Return PkgPublishingConfig (GitHub config, GCP config, and manual publishing restriction status).
  • Add unit and integration tests covering anonymous, non-admin, admin, matching GitHub Action OIDC, and mismatched GitHub Action OIDC callers.

Related Issues

Activity

  1. jonasfj commented on Sep 10, 2026

    @jonasfj
    Member

    We'd need to evaluate whether we need:

    • A launch tracking this change
    • Security review -- new authentication schemes (that we today only use on a narrow scope)
    • Privacy design review

    If we want this, we should perhaps consider:

    • To what extend can introspection of this meta-data be made public
    • Could we allow a publisher level GCP service-account with programmatic access
      As alternatives.
  2. kevmoo commented on Sep 10, 2026

    @kevmoo
    MemberAuthor

    @jonasfj just starting with a dart pub CLI command that uses your existing auth would be a great start. That way we could let any user (already authenticated w/ pub.dev) see the config they already have access to for pkg:???

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions