Add failing tests for issue #466: OAuth all-repo access #467
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
Adds failing tests that detect the bug reported in #466 where PDD CLI requests access to ALL repositories instead of allowing selective repository access.
Test Files
tests/test_get_jwt_token.pytests/test_e2e_issue_466_oauth_all_repo_scope.pyWhat This PR Contains
"repo,user"is hardcoded atpdd/get_jwt_token.py:251Root Cause
PDD CLI uses GitHub OAuth Apps with the
repo,userscope, which by architectural design grants access to ALL repositories. This is a fundamental limitation of GitHub OAuth Apps that cannot be worked around by changing scopes. TherepoOAuth scope always means "all repositories the user can access" - there is no OAuth scope that provides selective repository access.Location:
pdd/get_jwt_token.py:251- The DeviceFlow class hardcodesscope = "repo,user"Solution Required: Migrate from OAuth App to GitHub App for CLI authentication, which would allow users to install the app and select specific repositories during installation.
Test Behavior
These are regression tests that document the current buggy behavior:
Next Steps
Fixes #466
Generated by PDD agentic bug workflow - Step 10