* feat(channels): support local gh authentication Co-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com> * test(channels): align registry catalog test and visuals with optional GitHub token (#8461) * fix(channels): address review feedback for GitHub local gh auth (#8461) Treat a blank replacement of an optional secret as a clear so an existing GitHub channel can no longer ship an empty or whitespace-only PAT to the daemon. Reuse the shared missing-field predicate in the editor's GitHub credential validation, wrap malformed baseUrl failures in an actionable channel error, and surface sanitized gh stderr in local authentication failures. * fix(channels): address second-round review feedback for GitHub local gh auth (#8461) Pin the whitespace-only token gate, the bounded gh stderr sanitization, and the required-secret blank-replacement guard with mutation-resistant tests. Log the authenticated account identity on channel connect so an out-of-band gh auth switch is visible to operators. Align test secret-source fixtures with the SDK union and complete the design doc's change footprint. * fix(channels): address third-round review feedback for GitHub local gh auth (#8461) * fix(channels): address fourth-round review feedback for GitHub local gh auth (#8461) * fix(channels): address fifth-round review feedback for GitHub local gh auth (#8461) * fix(channels): address sixth-round review feedback for GitHub local gh auth (#8461) * fix(channels): address seventh-round review feedback for GitHub local gh auth (#8461) * fix(channels): address eighth-round review feedback for GitHub local gh auth (#8461) --------- Co-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com> Co-authored-by: qwen-code-ci-bot <qwen-code-ci-bot@users.noreply.github.com> Co-authored-by: qwen-code-dev-bot <qwen-code-dev@service.alibaba.com>
4 KiB
GitHub Channel local gh authentication
Problem
The GitHub Channel currently requires a classic personal access token in every configuration. This prevents Web Shell users from creating a channel that reuses the GitHub CLI authentication already available to the daemon host through gh auth login.
The separate Web Shell pull-request integration already relies on the daemon host's gh installation and authentication, but the Channel adapter passes only its configured token to Octokit.
Proposed behavior
- Keep an explicitly configured channel token as the highest-priority credential.
- Add an explicit
useLocalGhopt-in for reusing the daemon host's account-wide GitHub CLI credential. - When the token is absent and
useLocalGhis enabled, resolve a token by runninggh auth token --hostname <host>in the Channel worker. - Reject configurations that provide neither an explicit token nor the opt-in.
- Use
github.comas the localghauthentication hostname for the defaulthttps://api.github.comAPI URL. - Derive the hostname from a configured GitHub Enterprise
baseUrl. - Require
baseUrlto use HTTPS before resolving a daemon host credential through localghauthentication. - Fail Channel startup with actionable diagnostics when
ghis unavailable or the selected host is not authenticated. - Never persist or expose the token returned by
gh.
Changes
GitHub Channel plugin
Make the managed token secret optional, remove it from startup-required fields, and add a useLocalGh boolean. Update the descriptions to explain that an explicit classic PAT overrides local GitHub CLI authentication. The plugin's management descriptor validates the resolved configuration during managed upserts and rejects one that provides neither a token nor the opt-in, so the daemon mutation boundary keeps the immediate save-time rejection the required token provided before, while connect() still rejects configurations whose runtime credential cannot be resolved.
GitHub Channel adapter
Resolve credentials during connect() before constructing Octokit. Use execFile without a shell, a bounded timeout, and a bounded output buffer. Pass the selected hostname as a separate argument. The Channel worker already inherits the daemon's PATH, HOME, and related environment, so gh reads the daemon host's existing login.
Web Shell
The descriptor-driven editor already supports optional secret and boolean fields. Expose useLocalGh and require either a preserved/non-empty token or the explicit opt-in before saving. An existing PAT can be cleared only when local gh authentication is selected. Update localized field text accordingly.
Documentation
Document local gh auth login as an explicit opt-in and explicit PAT configuration as an override. Warn that the local credential is account-wide and preserve the recommendation to use a separate bot account because the authenticated account cannot trigger its own channel.
Files affected
packages/channels/github/src/index.tspackages/channels/github/src/GithubAdapter.tspackages/channels/github/src/GithubAdapter.test.tspackages/cli/src/commands/channel/channel-registry.test.tspackages/web-shell/client/components/channels/channel-editor-state.tspackages/web-shell/client/components/channels/channel-editor-state.test.tspackages/web-shell/client/components/channels/ChannelEditorDialog.tsxpackages/web-shell/client/e2e/visuals/screenshots.spec.tspackages/web-shell/client/i18n.tsxdocs/users/features/channels/github.mddocs/design/github-channel-gh-auth.md
Scope boundaries
- No automatic login or interactive
gh auth logininvocation. - No GitHub App or fine-grained PAT support.
- No shared cross-package GitHub credential abstraction.
- No change to GitLab Channel authentication.
Security considerations
The resolved token stays in memory and is passed only to Octokit. It is not written into settings or logs. The subprocess uses fixed arguments and no shell. Existing sender-policy and self-authored-comment protections remain unchanged.