Skip to content

Deleting a git token that pipeline stages use leaves the stages broken with an opaque error #8850

Description

@andypalmi

Summary

DELETE /api/v1/teams/:teamId/git/tokens/:tokenId deletes a token even when git-repository pipeline stages use it. The foreign key is ON DELETE SET NULL, so the stages are kept with no token and every later push or pull fails with a message that does not say why.

Steps to reproduce

  1. Create a git token and a pipeline stage that uses it (PUT /api/v1/pipelines/:id/stages/:stageId with gitTokenId).
  2. Delete the token. The response is 200.
  3. Fetch the stage: gitRepo.gitTokenId is now "". Trigger a deploy or pull on the stage.

Expected

Either the delete is refused with a 409 naming the pipelines that use the token, or the stage is marked clearly as having no token, and the push or pull error says the git token is missing.

Actual

PipelineStageGitRepo.deploy and .pull read gitToken.token from a null token inside their try block, so the stage ends in status error with the message Cannot read properties of null (reading 'token'). The UI shows that text.

References

  • forge/ee/routes/gitops/index.js:65-81 (delete route)
  • forge/db/migrations/20250408-02-EE-add-pipeline-stage-git-repo.js:45-50 (SET NULL)
  • forge/ee/db/models/PipelineStageGitRepo.js:95,104,147,159
  • forge/ee/db/views/PipelineStage.js:70 (encodeHashid(null) yields "")
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:apiWork on the platform APItype:bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions