fix(hands): migrate Reddit auth to client_credentials, document Twitter OAuth 1.0a

Reddit:
- Remove REDDIT_USERNAME and REDDIT_PASSWORD requirements (deprecated
  password grant)
- Switch to grant_type=client_credentials (app-only auth)
- Update system_prompt and SKILL.md auth examples

Twitter:
- Add optional OAuth 1.0a credentials (API key/secret, access
  token/secret) for user-context operations
- Document Bearer Token vs OAuth 1.0a authentication modes in SKILL.md
- Note which endpoints require user-context auth
This commit is contained in:
Evan Hu committed 2026-03-22 20:28:16 +09:00
1 parent 8923c4e0c3
commit fb45e39dcb
4 files changed
+94 -43

No files matched your search

+78
View File
@@ -59,6 +59,84 @@ steps = [
"Restart LibreFang or reload config for the change to take effect",
]
[[requires]]
key = "TWITTER_API_KEY"
label = "Twitter API Key (Consumer Key)"
requirement_type = "api_key"
check_value = "TWITTER_API_KEY"
optional = true
description = "OAuth 1.0a Consumer Key. Optional — only needed for user-context operations (liking, retweeting, following as a specific user)."
[requires.install]
signup_url = "https://developer.twitter.com/en/portal/dashboard"
docs_url = "https://developer.twitter.com/en/docs/authentication/oauth-1-0a"
env_example = "TWITTER_API_KEY=your_api_key_here"
estimated_time = "5-10 min"
steps = [
"Go to developer.twitter.com and open your App settings",
"Navigate to 'Keys and tokens' page",
"Copy the 'API Key' (also called Consumer Key)",
"Set it as TWITTER_API_KEY environment variable",
]
[[requires]]
key = "TWITTER_API_SECRET"
label = "Twitter API Secret (Consumer Secret)"
requirement_type = "api_key"
check_value = "TWITTER_API_SECRET"
optional = true
description = "OAuth 1.0a Consumer Secret. Optional — only needed alongside TWITTER_API_KEY for user-context operations."
[requires.install]
signup_url = "https://developer.twitter.com/en/portal/dashboard"
docs_url = "https://developer.twitter.com/en/docs/authentication/oauth-1-0a"
env_example = "TWITTER_API_SECRET=your_api_secret_here"
estimated_time = "2-3 min"
steps = [
"On the same 'Keys and tokens' page as the API Key",
"Copy the 'API Secret' (also called Consumer Secret)",
"Set it as TWITTER_API_SECRET environment variable",
]
[[requires]]
key = "TWITTER_ACCESS_TOKEN"
label = "Twitter Access Token"
requirement_type = "api_key"
check_value = "TWITTER_ACCESS_TOKEN"
optional = true
description = "OAuth 1.0a user Access Token. Optional — only needed for user-context operations."
[requires.install]
signup_url = "https://developer.twitter.com/en/portal/dashboard"
docs_url = "https://developer.twitter.com/en/docs/authentication/oauth-1-0a"
env_example = "TWITTER_ACCESS_TOKEN=your_access_token_here"
estimated_time = "2-3 min"
steps = [
"On the 'Keys and tokens' page, scroll to 'Authentication Tokens'",
"Generate an Access Token and Secret",
"Copy the Access Token",
"Set it as TWITTER_ACCESS_TOKEN environment variable",
]
[[requires]]
key = "TWITTER_ACCESS_TOKEN_SECRET"
label = "Twitter Access Token Secret"
requirement_type = "api_key"
check_value = "TWITTER_ACCESS_TOKEN_SECRET"
optional = true
description = "OAuth 1.0a user Access Token Secret. Optional — only needed alongside TWITTER_ACCESS_TOKEN for user-context operations."
[requires.install]
signup_url = "https://developer.twitter.com/en/portal/dashboard"
docs_url = "https://developer.twitter.com/en/docs/authentication/oauth-1-0a"
env_example = "TWITTER_ACCESS_TOKEN_SECRET=your_access_token_secret_here"
estimated_time = "2-3 min"
steps = [
"Generated alongside the Access Token above",
"Copy the Access Token Secret",
"Set it as TWITTER_ACCESS_TOKEN_SECRET environment variable",
]
# ─── Configurable settings ───────────────────────────────────────────────────
[[settings]]
+6
View File
@@ -19,6 +19,12 @@ Authorization: Bearer $TWITTER_BEARER_TOKEN
**Environment variable**: `TWITTER_BEARER_TOKEN`
**Authentication modes**:
- **Bearer Token only** (default): Sufficient for posting tweets, reading timelines, and searching. All core functionality works with just the Bearer Token.
- **Bearer Token + OAuth 1.0a** (optional): Required for user-context operations such as liking tweets, retweeting, following/unfollowing, and accessing DMs. Set `TWITTER_API_KEY`, `TWITTER_API_SECRET`, `TWITTER_ACCESS_TOKEN`, and `TWITTER_ACCESS_TOKEN_SECRET` to enable these features.
> **Note**: The Like endpoint (`POST /2/users/:id/likes`) and Retweet endpoint (`POST /2/users/:id/retweets`) require OAuth 1.0a User Context authentication. If only Bearer Token is configured, these operations will be skipped with a warning.
### Core Endpoints
**Get authenticated user info**: