canva-ci-integration

v2026.09.24

Build credential-free Canva contract tests with a separately protected live read. Use when testing adapters, OAuth boundaries, OpenAPI drift, fork behavior, or deployment readiness. Trigger with: "test Canva in CI", "add Canva contract tests", "secure Canva GitHub Actions".

GitHub
安装命令
npx skhub add jeremylongshore/canva-ci-integration
Markdown
SKILL.md

Canva Fork-Safe CI Contract Lane

Overview

Keep pull-request validation offline and deterministic. Reserve one minimal live read for trusted commits after environment protection, without rotating production tokens inside CI.

Prerequisites

  • Existing test framework and repository-defined command
  • Pinned Canva OpenAPI snapshot or validated fixtures
  • Protected environment with dedicated test integration and cleanup owner

Instructions

Step 1: Inventory workflow trust

Use Read and Grep to map pull-request events, fork execution, secret references, generated clients, artifact uploads, and any code path that creates Canva resources.

Step 2: Define offline contracts

Use Write or Edit to test request construction, error parsing, explicit-scope checks, async job states, redaction, and unknown response fields against fixtures.

Step 3: Pin provider inputs

Version the OpenAPI snapshot or its checksum and make drift visible. Do not silently regenerate clients during an unrelated test run.

Step 4: Add a protected live read

Use an approved test user to call a non-mutating identity or metadata endpoint. Assert authorization and response shape, not volatile content.

Step 5: Close secret boundaries

Do not use privileged pull-request events to run untrusted code. Keep client secrets and refresh tokens outside job logs, artifacts, caches, and fork contexts.

Step 6: Emit exact-head evidence

Record commit, commands, fixture version, live endpoint pattern, protected environment, redaction result, and cleanup status.

Authentication

Canva Connect calls use Bearer access tokens obtained by a backend through OAuth 2.0 Authorization Code with SHA-256 PKCE. Request explicit least-privilege scopes, keep client secrets and tokens out of browser-visible state, and serialize refresh so the replacement single-use refresh token is stored atomically.

Tool Discipline

Use Read and Grep for discovery and evidence. Use Write or Edit only for the approved artifact, code, configuration, test, or receipt described by this workflow; do not make an unapproved Canva-side change.

Output

  • Scoped decision or implementation artifact
  • Redacted operation and validation receipt
  • Failure, rollback, and follow-up ownership record

Examples

Every fork runs mocked OAuth and response fixtures. A protected main-branch job performs one user-identity read and fails closed when its expected credential is absent.

Error Handling

FailureResponse
Fork can reach secretsDisable the job and correct the event/environment boundary
CI rotates refresh tokensMove rotation to the application credential service
Fixture accepts unknown breakageUpdate the pinned contract and review the diff
Live test creates contentReplace it with a non-mutating identity or metadata read

Resources

发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

2026年9月24日

分类

未分类

许可证

MIT

源路径

skills/.curated/canva-ci-integration

默认分支

main

最新提交

e5a6c3b

Tree SHA

c2dc8e8