fix: avoid 422 when enterprise policy controls org fork setting - #3360
andrewesweet wants to merge 2 commits into
Conversation
|
👋 Hi! Thank you for this contribution! Just to let you know, our GitHub SDK team does a round of issue and PR reviews twice a week, every Monday and Friday! We have a process in place for prioritizing and responding to your input. Because you are a part of this community please feel free to comment, add to, or pick up any issues/PRs that are labeled with |
deiga
left a comment
There was a problem hiding this comment.
I think this won't be as simple as this. Since we use d.GetOk to identify if members_can_fork_private_repositories should be sent to the API it would still continue sending the value.
It would be important to add a test that verify's that members_can_fork_private_repositories isn't actually being set or updated in the Read function
08b4cec to
21524a1
Compare
andrewesweet
left a comment
There was a problem hiding this comment.
Thanks for the review, @deiga. I've updated the PR.
The schema now has Computed: true on the field, and the build function uses d.GetOkExists instead of shouldInclude. I followed the same pattern as allow_forking in resource_github_repository.go.
I also added:
- Unit tests for
buildOrganizationSettingscovering nil when omitted, non-nil when explicitly set totrueorfalse, and nil on updates when unchanged. - An acceptance test (
TestAccGithubOrganizationSettings_omittedForkFieldProducesCleanPlan) verifying no phantom diff after apply.
|
Requesting re-review please, @deiga |
| }) | ||
| } | ||
|
|
||
| func TestAccGithubOrganizationSettings_omittedForkFieldProducesCleanPlan(t *testing.T) { |
There was a problem hiding this comment.
issue: We don't use this pattern, please add the test the the function above
| if shouldInclude("members_can_fork_private_repositories") { | ||
| if !isUpdate { | ||
| if _, ok := d.GetOkExists("members_can_fork_private_repositories"); ok { //nolint:staticcheck // SA1019 // GetOkExists needed for Computed+Optional bool fields | ||
| settings.MembersCanForkPrivateRepos = new(d.Get("members_can_fork_private_repositories").(bool)) |
There was a problem hiding this comment.
issue: you haven't run make lintcheck-new, please do so
There was a problem hiding this comment.
issue: Please move the unit tests into the existing test file
| if _, ok := d.GetOkExists("members_can_fork_private_repositories"); ok { //nolint:staticcheck // SA1019 // GetOkExists needed for Computed+Optional bool fields | ||
| settings.MembersCanForkPrivateRepos = new(d.Get("members_can_fork_private_repositories").(bool)) | ||
| } | ||
| } else if d.HasChange("members_can_fork_private_repositories") { |
There was a problem hiding this comment.
question: the condition has changed here, is that on purpose?
There was a problem hiding this comment.
issue: this folder doesn't exist anymore, please rebase and follow the current docs convention
Remove Default: false from members_can_fork_private_repositories schema to prevent the field from being sent to the API when not explicitly set by the user. When an enterprise-level policy locks this setting, sending any value causes a 422 validation error. Without a default, the field is only included in API calls when the user explicitly configures it, matching the behavior of members_can_create_internal_repositories (enterprise-only field). Fixes integrations#2689 Relates to integrations#1333 Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Add Computed: true to members_can_fork_private_repositories schema so Terraform accepts API values when users omit the field, preventing phantom diffs that trigger 422 errors under enterprise policy. Replace shouldInclude with d.GetOkExists for this field since GetOk cannot distinguish "set to false" from "not set" on Computed+Optional bools. Follows allow_forking pattern in resource_github_repository.go. Add unit tests for buildOrganizationSettings and acceptance test proving no phantom diff after apply. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
73dfb5d to
d2a46a4
Compare
|
@andrewesweet please rebase and respond to open questions |
There was a problem hiding this comment.
Pull request overview
These provider review instructions are being used. This PR avoids organization-settings API 422 errors when enterprise policy controls private repository forking.
Changes:
- Makes the fork setting optional/computed and conditionally sends it.
- Adds unit and acceptance coverage.
- Documents the enterprise-policy interaction.
Reviewed changes
Copilot reviewed 4 out of 4 changed files in this pull request and generated 3 comments.
| File | Description |
|---|---|
github/resource_github_organization_settings.go |
Updates schema and API payload behavior. |
github/resource_github_organization_settings_unit_test.go |
Tests field inclusion and schema properties. |
github/resource_github_organization_settings_test.go |
Adds clean-plan acceptance coverage. |
docs/resources/organization_settings.md |
Updates user guidance. |
| - `members_can_create_public_pages` - (Optional) Whether or not organization members can create new public pages. Defaults to `true`. | ||
| - `members_can_create_private_pages` - (Optional) Whether or not organization members can create new private pages. Defaults to `true`. | ||
| - `members_can_fork_private_repositories` - (Optional) Whether or not organization members can fork private repositories. Defaults to `false`. | ||
| - `members_can_fork_private_repositories` - (Optional) Whether or not organization members can fork private repositories. When an enterprise policy controls this setting, omit this attribute to avoid API validation errors. |
| }) | ||
| } | ||
|
|
||
| func TestAccGithubOrganizationSettings_omittedForkFieldProducesCleanPlan(t *testing.T) { |
| Check: resource.ComposeTestCheckFunc( | ||
| resource.TestCheckResourceAttr( | ||
| "github_organization_settings.test", | ||
| "billing_email", "test@example.com", | ||
| ), |
Resolves #2689
Relates to #1333
Before the change?
members_can_fork_private_repositorieshasDefault: falsein the schema, causing the field to always be sent to the GitHub API even when not explicitly set by the user.After the change?
Default: falsefrom the schema so the field is only included in API calls when explicitly configured by the user.members_can_create_internal_repositories(enterprise-only field with no default).Users who never set this field see no behavioral change — the API default is
falseand the Read function still populates state from the API response.Pull request checklist
Does this introduce a breaking change?