mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 10:48:12 +02:00
fix: preserve GitHub sign-in and show connected repository access (#12993)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - GitHub connections give agents an account with selected repository access. > - Fresh local instances enroll with production Paperclip Cloud. > - Enrollment could finish while the GitHub OAuth profile remained disabled. > - Setup then switched to a personal access token form without explanation. > - This change preserves sign-in intent and shows the connected account and repositories. ## Linked Issues or Issue Description Related: #12907, #12943, #12947. Existing open GitHub connection work was checked. No duplicate was found. **What happened?** After Cloud enrollment, a fresh test-drive asked for a GitHub key. Production did not advertise the managed GitHub profile. Staging did. The permissions page also omitted the authenticated username and repository names. **Expected behavior** Continue with GitHub OAuth when available. Explain unavailable sign-in and allow retry otherwise. Show the GitHub username and complete accessible repository list. **Steps to reproduce** Start a fresh test-drive. Choose GitHub and complete instance enrollment while the Cloud GitHub profile is disabled. Open an existing GitHub connection's permissions page. ## What Changed - Preserve managed sign-in intent when the gallery omits its profile. - Refresh the selected gallery entry on retry without resetting the audience. - Fetch all pages of GitHub installations and repositories. - Store only repository IDs, full names, and installation IDs in grant metadata. - Show the GitHub username, repository list, management link, and refresh action. - Discard the repository snapshot after newer installation lifecycle events. Preserve snapshots verified after delayed events. - Lock and re-read grant metadata when applying installation events or saving refreshed access. Patch only webhook fields for other events. Reject snapshots if access changed during the external fetch, using unique access revisions even when timestamps collide. - Show repository installation recovery for managed OAuth even when the app also offers an advanced PAT method. - Update tests and the GitHub connection runbook. No SQL migration is required. ## Verification - Local typecheck, build, and token gates passed. All latest-head CI gates passed, including the complete test matrix and browser suites. Greptile is 5/5 with no unresolved findings. - All 382 focused setup, permissions, metadata, service, and webhook tests passed across final runs. One socket-hang-up test passed on rerun with the full service suite. Final service, metadata, and webhook checks passed all 230 tests. - The broad local suite was stopped after failures. Seven workspace-runtime exposure and control-conflict failures reproduce on base commit `54a99d884`. The broad run also overlapped local iteration; final focused tests and clean-checkout CI are tracked separately. - Browser: a fresh production-backed instance completed enrollment, retried after profile enablement, reached GitHub consent, recovered from a missing installation, and completed OAuth. - Browser: the permissions page showed the authenticated username and the selected private test repository. A real `get_me` call returned the same account. Reading the selected repository passed; reading an unselected private repository failed with 404. - Browser: a second fresh instance completed enrollment and OAuth without a PAT form or unavailable state. Its username and repository list survived reload and refresh. A real get_me call on the final code returned the displayed account. ## Risks - Repository names are now stored in company-scoped grant metadata and shown with that credential. They are display data, not authorization data. - Large selections require more GitHub API calls. A failed later page rejects the refresh rather than reporting a partial list. - Older grants and webhook-invalidated snapshots require Refresh access to load the list. - Cloud profile enablement is separate deployment configuration. This PR does not change OAuth scopes or GitHub App permissions. ## Model Used OpenAI GPT-6 (`gpt-6-astra`) via Codex. Reasoning, code execution, and browser tools were used. The exact context window size was not exposed. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>
This commit is contained in:
1 parent
54a99d8840
commit
bac60d9d31
12 files changed
+340
-103
No files matched your search
@@ -69,15 +69,26 @@ installation-health failure, not as token expiry.
|
||||
|
||||
## Repository access
|
||||
|
||||
OAuth completion verifies `/user`, `/user/installations`, and each
|
||||
installation's accessible repository count. Setup remains incomplete until at
|
||||
least one installation and repository are available. Paperclip stores user and
|
||||
installation summaries, not a repository-name cache. GitHub stays authoritative:
|
||||
removed repository access fails immediately even if a displayed count is stale.
|
||||
OAuth completion verifies `/user`, every page of `/user/installations`, and every
|
||||
page of each installation's accessible repositories. Setup remains incomplete
|
||||
until at least one installation and repository are available. Paperclip stores
|
||||
the authenticated username and a grant-scoped display snapshot containing only
|
||||
repository IDs, full names, and installation IDs. GitHub stays authoritative:
|
||||
this snapshot never authorizes repository access.
|
||||
|
||||
The Apps UI links to GitHub's installation management page and offers
|
||||
**Refresh access**. Selected repositories are recommended. Choosing all
|
||||
repositories requires an explicit warning in setup.
|
||||
The permissions page shows the authenticated GitHub account and the complete
|
||||
accessible repository list. **Refresh access** reloads it from GitHub. Older
|
||||
grants and grants invalidated by newer installation lifecycle events prompt for a
|
||||
refresh instead of presenting a stale list. The page links to GitHub's
|
||||
installation management page. Selected repositories are recommended; all-
|
||||
repository access retains its warning.
|
||||
|
||||
Fresh local test-drives use production Paperclip Cloud. Instance enrollment
|
||||
and provider enablement are separate: enrollment alone does not enable GitHub
|
||||
OAuth. Production must advertise the `github.code` profile (see Cloud's
|
||||
`docs/github-connector-deploy-bootstrap.md`). If it is unavailable, setup
|
||||
preserves the sign-in intent and offers a retry instead of silently switching
|
||||
to a personal access token. A successful retry preserves the chosen audience.
|
||||
|
||||
## Webhooks
|
||||
|
||||
|
||||
Reference in new issue
Block a user