* authentication: separate enterprise provider and engine lifecycles
Keep the single configured enterprise instance and native account identities, while owning engine replacement, registration-safe session events and cleanup separately. Isolate OAuth callbacks by host and preserve the current Microsoft-brokered flows.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: discard superseded enterprise startup failures
Version enterprise configuration updates so a failed initial update cannot enqueue an error state after a newer configuration succeeds. Cover both A-to-B and A-to-B-to-A races through extension activation while preserving current-error fallback and later recovery.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: serialize enterprise failures and session publication
Remove activation generation bookkeeping by handling failure state inside each queued update. Reconcile preparation-time session removals, additions and changes before publishing a replacement, with regression coverage for consecutive initialization failures and pending-host events.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: own event buffering at the registration boundary
Buffer initial provider events in the extension host until its registration RPC completes. Remove the extension-side wrapper, microtask readiness inference and construction factory; directly construct a host-bound session engine with a side-effect-free cached session inventory. Preserve broker flows and exercise registration ordering through core RPC tests.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: clarify disposal and registration ownership
Keep the bundled README focused on user setup. Name disposal cancellation explicitly, verify cleanup while an engine is still being prepared, and clarify why core captures session events before awaiting registration.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: Add GitHub session issuer provenance
Expose optional session authorizationServer metadata through authIssuers and authentication RPCs, populate it for GitHub sessions, and route in-repository consumers from the selected session. Keep existing single-host configuration and account-selection behavior.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: Preserve public static-token MCP sessions
Keep issuer validation on the enterprise MCP path and preserve the fixed public endpoint for static-token authentication. Cover definition creation and resolution using StaticGitHubAuthenticationService.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* i18n: Register workbench GitHub service translations
Register the service's new localized authentication error with the workbench translation project so the CI translation-reminder rule passes.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>