Add programmatic device-code login to CopilotClient
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 35/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Ít trao đổi
- Công nghệ
- csharp
- Lĩnh vực
- api, authentication
Hướng nghiên cứu
Bắt đầu từ CopilotClient, GetAuthStatusAsync, CopilotClientOptions và cơ chế xử lý thông tin xác thực ~/.copilot hiện có để lập bản đồ luồng xác thực và trạng thái của máy khách RPC. Xác định hành vi của LoginAsync, LoginOptions, DeviceCodePrompt, AuthResult và LogoutAsync tùy chọn, sau đó xác minh rằng việc đăng nhập thành công sẽ cập nhật trạng thái xác thực và cho phép sử dụng models.list và session.send mà không cần khởi động lại máy khách.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Problem
CopilotClient exposes GetAuthStatusAsync so callers can detect an unauthenticated state, but there is no SDK method to transition the session into an authenticated one. The only auth inputs today are:
CopilotClientOptions.GitHubTokenGITHUB_TOKEN/GH_TOKENenv vars- Pre-existing cached credentials under
~/.copilot/from a prior interactivecopilot /loginrun
This works on machines where credentials have already been seeded — typical on Windows where the Copilot Chat extension or gh copilot may have populated the cache — but on a fresh macOS or Linux install there is no in-SDK path to bootstrap auth. The only options are:
- Require the caller to supply a Personal Access Token. PATs are blocked by policy in many environments and can't be issued at all for some account types.
- Launch the bundled CLI binary (
runtimes/<rid>/native/copilot) out-of-band and have the user run/logininteractively, then re-enter the SDK once the credential file lands on disk.
Option 2 forces every SDK consumer to:
- Locate the bundled CLI binary across RIDs.
- Manage an external process lifecycle (cancellation, orphan cleanup, exit-code handling).
- Surrender stdio to the embedded CLI, which precludes custom UX, headless flows, and structured logging.
- Bypass the SDK's normal RPC contract entirely for this one capability.
Proposal
Add a programmatic device-code OAuth flow to CopilotClient that yields the verification URL and user code via a callback (or an IAsyncEnumerable of state events) so consumers can render the prompt in their own UI:
public Task<AuthResult> LoginAsync(
LoginOptions options,
CancellationToken cancellationToken = default);
public sealed class LoginOptions
{
/// Invoked once with the device code + verification URL the user must visit.
public Action<DeviceCodePrompt>? OnDeviceCode { get; init; }
/// Optional override for the OAuth client / scopes if the SDK supports more than one tier.
public string? ClientId { get; init; }
}
public sealed record DeviceCodePrompt(
string UserCode,
Uri VerificationUri,
TimeSpan ExpiresIn,
TimeSpan PollInterval);
public sealed record AuthResult(
bool Success,
string? AccountLogin,
string? FailureReason);
After LoginAsync returns successfully, GetAuthStatusAsync should reflect the new state and subsequent RPC calls (models.list, session.send, etc.) should succeed without restarting the client.
A complementary LogoutAsync() that clears the cached credentials would round out the surface but is lower priority.
Why this belongs in the SDK
- Parity with
gh auth, Octokit's device flow, and the VS Code Copilot extension — all of which provide a programmatic device-code path. The SDK is the only Copilot client that requires shelling out to authenticate. - No-PAT bootstrap — enables the SDK to be used in environments where PATs are unavailable or restricted, without forcing a separate CLI install.
- Single source of truth for credential storage — the SDK already reads
~/.copilot/; centralizing the write path here prevents callers from drifting if the storage format changes. - Cancellable, awaitable, structured — replaces an opaque interactive subprocess with a normal async API that cooperates with
CancellationToken, structured logging, and host-defined UX. - Headless / CI scenarios — a callback-based device flow can be driven by automation (forwarding the code to chat, email, a webhook, etc.); an interactive subprocess cannot.
Alternatives considered
- Document the shell-out — pushes the same complexity into every SDK consumer.
- Expose a
LoginUri/LoginPollpair instead of a singleLoginAsync— more flexible but pushes polling logic onto callers. - Reuse
gh authtokens — only works whereghis installed and authorized for the right account; not portable and still needs an external tool.
A first-class LoginAsync on CopilotClient is the smallest API addition that closes the gap.
- Ngôn ngữ chính
- TypeScript
- Star
- 10.5k
- Fork
- 1.5k
- Merge trung bình
- 1 ngày 11 giờ
- Pull request đã merge (30 ngày)
- 81
Chuẩn bị môi trường
Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của github/copilot-sdk
-
Clarify SDK architecture and in-process runtime transportCó thể đã có người làm @KalebCole đã nhận 3 ngày trước. Đang mởdocumentation
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 92/100
github/copilot-sdk#2804 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Python ModelLimits drops max_output_tokens from model metadataCó thể đã có người làm @HDMowri đã nhận 5 ngày trước. Đang mởbug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
github/copilot-sdk#2798 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
github/copilot-sdk#2793 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
agentic-workflows
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
github/copilot-sdk#2782 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Rust: subagent lifecycle hooks are logged as unknownCó thể đã có người làm @hackberry-lab đã nhận 7 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
github/copilot-sdk#2781 ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của github/copilot-sdk
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 4 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày