This branch previously carried a full copy of the app, which was wrong twice:
it drifted behind main (11 commits by the end), and syncing it meant
`git merge origin/main`, which silently replaced the three instance manifests
with main's public placeholders — no conflict raised, because only main had
touched those paths.
As an orphan branch with no shared history there is nothing to sync and
nothing to clobber. Clone drops from 1.5M to ~200K. Verified: installing from
this ref yields the same server URL, client ID and callback port as before.
Previous tip was e5abd34 if any of the dropped history is ever wanted.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
1.7 KiB
instance/dnspegasus
This branch is not a fork of the project. It is an orphan branch holding exactly three files: the Claude Code plugin manifests for one live instance, filled in with that instance's real server URL and OAuth client ID.
.claude-plugin/marketplace.json marketplace named `dnspegasus`
plugin/.claude-plugin/plugin.json plugin manifest
plugin/.mcp.json server URL + pre-registered OAuth client
Install from it with a #ref fragment:
claude plugin marketplace add "https://repo.anhonesthost.net/cybercove-labs/shared-memory.git#instance/dnspegasus"
claude plugin install shared-memory@dnspegasus
Why it's an orphan branch
It used to be a normal branch off main, which was wrong twice over:
- It carried a full copy of the application it had no reason to have, so it
drifted behind
mainand a stale deploy could have been cut from it. - Syncing it meant
git merge origin/main, which silently replaced these three manifests withmain's public placeholders. No conflict was raised, because onlymainhad touched those paths.
With no shared history there is nothing to sync and nothing to clobber. Never
merge main into this branch — if the manifest format changes upstream,
hand-edit these files and run claude plugin validate ..
main carries the same three files with placeholder values, as the public
template. The real values live only here.
The client ID is not a secret
clientId is a Public (PKCE) OAuth client. It is meant to be committed —
it identifies the client, it does not authenticate it. Access is controlled by
the bindings on the IdP application, not by keeping this string private.