Refactor createDependentPR to use http.extraHeader for auth#1412
Open
issuetopr-dev[bot] wants to merge 2 commits intomainfrom
Open
Refactor createDependentPR to use http.extraHeader for auth#1412issuetopr-dev[bot] wants to merge 2 commits intomainfrom
issuetopr-dev[bot] wants to merge 2 commits intomainfrom
Conversation
… in remote URLs\n\n- In createDependentPR workflow, stop setting tokenized remote URLs. Keep origin as a clean https URL and inject Authorization header per git command using for fetch, pull, and push.\n- Update SyncBranchTool (both app and shared) to push with ephemeral Authorization header instead of mutating the remote URL.\n- Update pushBranch helper (both app and shared) to use per-command header and avoid persisting credentials.\n\nThis hardens auth handling so tokens are not written to .git/config or logged in remote URLs.
Contributor
|
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the Note Free review on us!CodeRabbit is offering free reviews until Wed Dec 17 2025 to showcase some of the refinements we've made. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
git -c http.https://github.com/.extraHeader="Authorization: bearer <token>" push ...so credentials are never persisted in .git/config.Details
git remote set-url origin "https://x-access-token:<token>@github.com/..."usage.git -c http.https://github.com/.extraHeader="Authorization: bearer <token>" <command>https://github.com/<owner>/<repo>.git.Files changed
Rationale
-coptions so nothing is persisted.Notes
pnpm run lint. Prettier and full type checks are not part of the normal CI workflow here, and running them locally flags pre-existing issues unrelated to this change.Closes #1410