fix(gh-wrapper): resolve the owner from orgs/ and users/ api endpoints - #397
Merged
Merged
Conversation
gh api orgs/OWNER/... and users/OWNER/... named an owner but fell through
to the cwd remote, so the cwd owner's token listed an org's repos (public
only, HTTP 200). Resolve them like repos/OWNER/.... The anchor, optional
leading slash and {owner} placeholder rule are unchanged.
Closes #396
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
_gh_wrapper_resolve_ownertook agh apicall's owner only fromrepos/OWNER/.... It now also readsorgs/OWNER/...andusers/OWNER/...(leading slash optional,{owner}placeholder ignored, first matching argument wins,^anchor kept so flag values like-f q=orgs/Zdo not match). Every other path is unchanged.Before:
gh api orgs/nightowlstudiollc/reposfrom a non-NOS checkout used the cwd owner's token and returned public repos only (HTTP 200, no error), so fleet surveys under-counted silently.Callers of the resolved owner
_gh_wrapper_sync_identity):orgs/Xandusers/Xnow pickGH_TOKEN_<X's var>, the same asrepos/X. An owner outside the three known ones keepsGH_TOKENas given. This is the intended fix._gh_wrapper_block_off_org_promotion,_gh_wrapper_force_draft_for_off_org): thegh apicheck fires only for a POST to apullsendpoint, which neitherorgs/norusers/shapes. Agh api orgs/X/...call cannot trigger it. Read from the code, not exercised with a new test; the existing off-org guard test still passes.Tests
bash/tests/test-gh-wrapper-token-select.sh(both standalone and function modes) gains:orgs/X,/orgs/X,users/X,/users/Xselect X's token;orgs/{owner}andusers/{owner}fall back to cwd;-f q=orgs/Zdoes not match; the first matching endpoint wins. Existingrepos/X/Ycases cover the unchanged path.bash-tests.Closes #396