Relationships
#3097 Docs: describe the private-entitlement registry check and the refusal wording in the extension publishing reference
Opened by skunk-ape · 10/6/2026
What changed
swamp CLI PR swamp/swamp#2875 (Lab #1545, released in v20261006.183549.0-sha.84495bbf) changed how swamp extension push handles a private publication the registry refuses on entitlement.
- A fifth registry check, private-entitlement, runs whenever the intent is private, in the dry run and the real push alike. It is decided from the collectiveEntitlements the push's existing whoami call returns (Lab #1544). A paid plan passes; a free plan with an active trial passes; a free plan whose trial has ended fails with the message: Collective "@acme" is on the Free plan and its trial ended on 2026-08-19. Private publication requires a paid plan; upgrade at https://swamp-club.com/o/acme/billing.
- A free plan with no trial, or a registry that reports no entitlement, is reported as not-run with cause entitlement-undecided; the dry run stays green and the registry decides at publish (its own gate may start the collective's trial).
- When the registry refuses with its 403, the CLI prints the registry's sentence followed by what the registry had reported for the collective at sign-in (plan, trial standing), phrased as a report. It names no plan the registry did not send; when none was reported it says so.
- Nothing about plan or trial is cached on disk. swamp auth whoami output is unchanged.
Which manual page needs updating
content/manual/reference/extensions/publishing.md
- The 403 row in the registry publication API error table says only "Namespace, token scope, or explicit-private entitlement denied." Add that the CLI reports the explicit-private refusal together with the collective's plan and trial standing as whoami reported them, and that a dry run reports the same verdict ahead of time as the private-entitlement check.
- The "Private publication" section (around the paragraph beginning "An explicit private choice, including one recovered during confirmation, also requires private-extension entitlement") should mention that swamp extension push --dry-run --visibility private now reports private-entitlement among its registry checks, with the three outcomes above (passed, failed, undecided) and their causes.
- The sentence noting that the CLI release v20260916.202907.0-sha.b07863c9 has no visibility flag is stale; the flag exists and the dry run now reports entitlement.
Optionally, content/manual/how-to/extensions/create-and-publish.md could show the refusal message so an author recognises it.
Suggested content
A short subsection under Private publication:
"When you publish privately, the CLI checks the collective's entitlement from the same whoami answer it uses for membership. A paid plan, or a free plan with an active trial, passes. A free plan whose trial has ended fails before upload with a message naming the collective, its plan and its billing page. Other standings are left to the registry, which decides at publish. If the registry refuses, the CLI repeats the registry's reason and adds what the registry had reported for the collective at sign-in. The CLI never caches your plan."
Refs Lab #1545, #1544, #3016. CLI-side wording is pinned by tests in src/domain/extensions/extension_publish_checks_test.ts and documented in design/primitives/extensions.md.
Closed
No activity in this phase yet.
skunk-ape commented 10/6/2026, 10:58:10 PM
Done in swamp-club PR #1298 (https://github.com/swamp-club/swamp-club/pull/1298, merge f928fe38), which folded this issue into the #3071 manual update. Samples are real output from swamp 20261006.221608.0-sha.5c0c6532. Closing.
Sign in to post a ripple.