Skip to content

Private repositories of a personal-account owner never appear, even with that owner's token set #465

Description

@matt-edmondson

What's wrong

SyncGitHubRepoInfoForOwner (ProjectDirector/ProjectDirector.cs:1006-1011) lists an owner's repositories with GitHubClient.Repository.GetAllForUser(owner), i.e. GET /users/{owner}/repos. GitHub documents that endpoint as returning public repositories only, even when the request is authenticated as that same user. Only Organization owners get the additional GetAllForOrg call, which does return private repos the token can see.

So the per-owner token (Set GitHub Owner Token, credential selection at ProjectDirector.cs:1226-1236 / 314-328) only helps organizations; for a User owner it changes nothing about what gets listed.

Failure scenario

  1. Add owner alice (a User account) and set alice's PAT via "Set GitHub Owner Token".
  2. Scan > GitHub Owners.
  3. Only alice's public repositories are listed; her private ones never show up, so they cannot be cloned, compared, or used as propagation targets from the app.

Suggested fix

  • Resolve the authenticated login (GitHubClient.User.Current()). When the owner is a User and equals that login (case-insensitive), list with GitHubClient.Repository.GetAllForCurrent(new RepositoryRequest { Affiliation = RepositoryAffiliation.Owner }).
  • Keep GetAllForUser for other users (where public-only is correct).
  • Natural to land alongside the async/exception-handling cleanup tracked in Scanning or adding a GitHub owner crashes on a 404/401/rate limit instead of skipping the owner #444, but independent of it.

Activity

  1. matt-edmondson commented on Oct 6, 2026

    @matt-edmondson
    ContributorAuthor

    Triage

    • Category: Bug
    • Priority: Medium. For User owners, the per-owner token has no effect on listing, so private repos can't be cloned, compared, or used as propagation targets. Nothing crashes, and organization owners are unaffected.
    • Suggested area / assignment: ProjectDirector/ProjectDirector.cs GitHub sync (SyncGitHubRepoInfoForOwner)
    • Duplicates / related: None found. Related to the async and exception cleanup in Scanning or adding a GitHub owner crashes on a 404/401/rate limit instead of skipping the owner #444, but independent of it.
    • In progress: No open PR covers it.

    Recommended next step: When the owner equals the authenticated login, branch to GetAllForCurrent(Affiliation = Owner). Test it with a mocked client, since the live API can't run in CI.


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions