Blocks a native client (#11, #12).
There is no way to list a directory or read a file through the API. The registry has repo grep and repo log, but nothing returning file contents, and the web's /raw and tree routes authenticate through s.viewer(), which reads the session cookie only — a bearer token gets nothing there.
Verified: a read-scoped token against /api/v1/cmd has no command that can open a file. For a public repo a client could scrape /raw anonymously; for a private one there is no path at all.
Add two control commands, so CLI, API and web all gain them at once:
- repo tree <owner/name> [--ref ] [] — entries with type, mode, size, and the sha, so a client can cache by object id
- repo cat <owner/name> [--ref ] — contents, base64 for binary, honouring limits.max_blob_bytes and reporting truncation
Both read-only, both fine over bare ssh.
closed by commit 40dab3e11b by cmc: control: repo tree and repo cat
2026-08-27 03:54 UTC