github implementation
Device flow ownership
Internally, src/deviceFlow.ts owns request transitions, completion checks and cleanup, using the service's existing store and auth adapter. GitHubService remains the route/tool facade and the sole owner of token migration, account-scoped secrets, mapping validation and credential commit/rollback. The device-flow owner receives only profile lookup, mapping validation and connection commit operations. Plugin shutdown marks active requests interrupted before calling the adapter's stopAll, then retries directory cleanup; it does not replace stopAll with individual cancellations. Pull-request details use GitHubClient.reviews for the review projection while files and reviews load concurrently.
GitHubDeviceFlow.currentFlow(userId) is the account-scoped source for pending and completing login state. GitHubService.connectionStatus, the initial start check and the fresh query after a failed flow insert use this same projection. It returns null when no active request exists and omits the private authentication directory. A concurrent insert is translated to auth_in_progress only when the fresh projection finds an active request; unrelated insertion failures propagate. The existing partial unique SQLite index still enforces one active request per account. Confirmation failures in both device login and repository actions use the stale factory in src/errors.ts, preserving state_changed, HTTP 409 and the original wording. Confirmations remain consumed before stale-state validation.
Managed command execution
Managed publication resolves the live Sandbox control for each command and calls runCommand with the explicit managed Project, account id, roots: [], leaseKind: 'github', a 60000 ms timeout and a combined 1 MiB output limit. Core owns preparation checks, capture, heartbeat, cancellation and lease release. GitHub retains its typed nonzero, output-limit and access-refusal mapping through the shared error helpers. Bundle creation marks temporary guest ownership through onStart after preparation is accepted, so a refused target is not followed by another refused cleanup. Host publication retains its actual runner and the credential broker's confined prepared.launch.env.
Browser runtime contract
The GitHub account panel, account summary chip and Project repository panel register against host UI API 55. The local browser runtime uses ElowenUiRuntime['api'] and ElowenUiRuntime['utils']['interpolate'] directly. For example, the Project panel sends api(path, { method: 'POST', json: payload }) and formats connectedBy through interpolate(template, { login }). The host owns JSON serialization, authentication, cancellation and placeholder handling. JSON and raw bodies are mutually exclusive in the host request type. Without a GitHub UI registration the host mounts no GitHub surfaces; an older host must refuse the registration instead of mounting missing capabilities.