Skip to content

🔑 feat: Allow Installation-Scoped GitHub Tokens for Trusted Workers - #263

Merged
danny-avila merged 2 commits into
mainfrom
danny-avila/github-installation-scope
Sep 27, 2026
Merged

danny-avila merged 2 commits into
mainfrom
danny-avila/github-installation-scope

Conversation

@danny-avila

Copy link
Copy Markdown
Collaborator

Summary

Commands on a trusted VM currently receive a token restricted to the repository selected when the command starts. Starting in one checkout and using cd or git -C to push another repository in the same GitHub organization therefore fails with 403 even when the App installation includes both repositories.

I added an opt-in installation token scope. The worker still resolves the App installation from the admitted checkout, but asks GitHub for a token covering the repositories that installation permits. GitHub's repository selection and App permissions remain the authority. The default remains a token restricted to one repository.

  • Add --github-token-scope installation and LIBRECHAT_CODE_GITHUB_TOKEN_SCOPE=installation, restricted to trusted VM App workers without a fixed installation ID.
  • Share concurrent token requests by installation and refresh installation-scoped tokens and repository-to-installation mappings after two minutes so new grants and transfers take effect without a worker restart.
  • Document the scope and the remaining requirement to start commands in the target organization when crossing organizations.

Flow

command cwd -> admitted checkout -> repository installation
                                    -> installation token cache
                                    -> existing masked Git/gh credentials

Change Type

  • New feature (non-breaking change which adds functionality)
  • This change requires a documentation update

Testing

From packages/code, I ran npm run build and node --test dist/github.test.js dist/cli.test.js: 51 passed. The new tests cover same-installation token sharing, separate organization installations, permission refresh, repository transfer, and CLI admission.

Test Configuration

Node 24.16.0 on macOS. No live worker was restarted for this PR.

Checklist

  • My code adheres to this project's style guidelines
  • I have performed a self-review of my own code
  • I have made pertinent documentation changes
  • My changes do not introduce new warnings
  • I have written tests demonstrating that my changes are effective or that my feature works
  • Local unit tests pass with my changes

@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-27T15:39:41.442650Z e4022d5 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e78dfe33b5

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/code/src/github.ts Outdated
? cachedInstallation &&
now.getTime() - (this.installationIdCachedAt.get(repository!) ?? 0) < GITHUB_INSTALLATION_CACHE_MS
? cachedInstallation
: await this.resolveInstallationId(repository ?? '', await this.appJwt(now), signal)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Bound the initial installation lookup with the shared timeout

When installation scope has a cold or two-minute-old repository mapping, this lookup runs before the shared request is created and receives only the caller's signal. Unlike the repository-scoped path below, it therefore bypasses GITHUB_SHARED_REQUEST_TIMEOUT_MS: a direct getCredential call without a signal can hang indefinitely, while worker calls can consume the remainder of the assignment deadline if GitHub accepts the connection but never responds. Perform this lookup with a bounded/shared signal as well.

Useful? React with 👍 / 👎.

@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review the latest head

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 🚀

Reviewed commit: e4022d5bb4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@danny-avila
danny-avila merged commit b03582a into main Sep 27, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants