[bug] GitHub App installation tokens (ghs_) are rejected by the credential preflight
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 48/100
- Tipo de issue
- Error
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- github, typescript
- Área
- authentication, backend
Línea de trabajo
Start in packages/backend/src/github.ts at getGitHubReposFromConfig and the GET /user preflight around lines 115 and 185; compare the existing token detection and authentication handling in github.ts and utils.ts:163-177. Check the existing GitHub token-type unit test and verify that a ghs_ token can discover repositories without the user-only preflight failing; consider the users: paths at lines 251 and 322 as additional scope.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Describe the bug
Sourcebot recognises GitHub App installation tokens as a supported token type —
GitHubTokenType declares 'app_installation' and detectGitHubTokenType() returns it
for the ghs_ prefix (packages/backend/src/github.ts:26,43), with a unit test asserting
exactly that.
However, a connector configured with one fails before listing a single repository.
getGitHubReposFromConfig validates the credential with GET /user (github.ts:185) and
rethrows on failure. An installation token authenticates as an installation, not a user,
so GitHub answers:
403 "Resource not accessible by integration"
No permission grant can satisfy this, because there is no user to return. The check also
cannot be skipped: its guard is isAuthenticated: !!token (github.ts:115), so the only
way to avoid it is to configure no token at all — which limits indexing to public
repositories.
Expected: a connector configured with an installation token indexes normally.
Actual: repository discovery aborts with a 403 at the preflight.
The inconsistency is the bug: every other GitHub path already handles installation
tokens correctly. getRepoAuth builds x-access-token: <token> git credentials from one
(utils.ts:163-177), which is precisely the documented form for installation tokens, and
repos.listForOrg accepts one. Only the preflight rejects it.
Note - The credential is simply an installation token supplied as an ordinary
connector token.
To reproduce
- Register a GitHub App, install it on an organisation, grant
Contents: readand
Metadata: read. - Mint an installation token:
POST /app/installations/{installation_id}/access_tokens(returns aghs_…token). - Configure a GitHub connector with that token and an
orgsentry:{ "type": "github", "token": { "env": "GITHUB_TOKEN" }, "orgs": ["my-org"] } - Start Sourcebot and trigger a connection sync.
Result: sync fails immediately. Logs show Failed to authenticate with GitHub and a 403
Resource not accessible by integration. Zero repositories are discovered.
Substituting a personal access token for the same organisation works, which isolates the
failure to the token type rather than to permissions or configuration.
Sourcebot deployment information
Sourcebot version (e.g. v3.0.1): v5.1.12 (docker.sourcebot.dev/sourcebot-dev/sourcebot),
also reproduced against main at the time of writing.
Additional information
Two further user-context calls exist in the same file and will fail the same way for the
same reason, though only when users: is configured rather than orgs::
repos.listForAuthenticatedUser→GET /user/repos(github.ts:251)rest.search.repos→GET /search/repositories?q=user:…(github.ts:322)
A fix for the preflight is proposed in the linked pull request. Happy to extend it to
those two paths if you would prefer them handled in the same change.
- Lenguaje dominante
- TypeScript
- Estrellas
- 3.9k
- Forks
- 374
- Merge medio
- 21 h 18 min
- PR fusionados (30 d)
- 39
Guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de sourcebot-dev/sourcebot
-
bug triage needed
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
sourcebot-dev/sourcebot#1681 · 1 comentario ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
sourcebot-dev/sourcebot#1633 ·
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
sourcebot-dev/sourcebot#1384 · 4 comentarios ·
-
ask_sb bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
sourcebot-dev/sourcebot#1137 · 4 comentarios ·
-
Feature
Dificultad 4/5 3-5 días Aptitud para principiantes 50/100
sourcebot-dev/sourcebot#1659 · 1 comentario ·
Todos los issues de sourcebot-dev/sourcebot
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
safetrustcr/dApp-SafeTrust#426 ·
-
area:workflow bug ready-for-agent
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
fil-donadoni/tolaria#4409 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
Fission-AI/OpenSpec#1960 ·
-
Add dependabot Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
corsairdev/corsair#1764 ·