Skip to content

fix(server): stop sending self-hosted Bitbucket repositories to Bitbucket Cloud - #14593

Open
BerkayClik wants to merge 3 commits into
pingdotgg:mainfrom
BerkayClik:fix/bitbucket-self-hosted-cloud-calls
Open

BerkayClik wants to merge 3 commits into
pingdotgg:mainfrom
BerkayClik:fix/bitbucket-self-hosted-cloud-calls

Conversation

@BerkayClik

@BerkayClik BerkayClik commented Oct 1, 2026 •

Copy link
Copy Markdown

Problem

A remote on a self-hosted Bitbucket Server / Data Center host (e.g. https://bitbucket.example.com/scm/<project>/<repo>.git) is classified as bitbucket, but the Bitbucket client only speaks Bitbucket Cloud. So the pull-request sync sweep, the pull-request browser, branch PR status and PR creation all send requests (with any configured Cloud credentials) to api.bitbucket.org for a repository that lives on another server. The reporter saw thousands of these requests in their traces.

Fixes #14591.

Change

As proposed in the triage: don't call the Cloud API for a host other than bitbucket.org unless a Cloud base URL was explicitly configured (T3CODE_BITBUCKET_API_BASE_URL).

  • PullRequestService.listWorkspaceProjects: such a Bitbucket host gets no implementation, so it goes down the existing unimplemented-host path ("This host cannot be browsed here yet."). PR sync and the browser no longer read it.
  • BitbucketApi.resolveRepository: such a remote is not resolved, so branch status, PR creation and checkout fail with BitbucketRepositoryRemoteNotFoundError before any request goes out. A named Bitbucket context that is rejected fails outright instead of falling back to another (Cloud) remote in the same checkout, so a mixed-remote checkout can't have the operation land on a different repository.
  • Both read one exported BitbucketApiBaseUrlConfigured config, so the escape hatch stays defined in one place.

bitbucket.org behavior is unchanged. Bitbucket Server / Data Center support itself is out of scope; it's tracked in #10837.

Scope and approval

Triaged bug with the intended behavior spelled out in the triage comment: #14591 (comment) ("don't call the Cloud API for any host other than bitbucket.org unless a Cloud base URL was explicitly configured. Those checkouts should be marked unsupported for pull-request sync and the pull-request browser.")

Verification

  • New tests:
    • PullRequestService.test.ts: a bitbucket.example.com project is listed as an unconfigured host and its provider is never asked, while a bitbucket.org project next to it still is. With T3CODE_BITBUCKET_API_BASE_URL set, the self-hosted project is read again.
    • BitbucketApi.test.ts: listPullRequests for a self-hosted remote fails with BitbucketRepositoryRemoteNotFoundError and makes no HTTP call. With the base URL set, it requests <base>/repositories/proj/repo/pullrequests as before. A self-hosted context in a checkout that also has a bitbucket.org remote fails the same way, with no HTTP call.
  • vp test run on BitbucketApi, BitbucketSourceControlProvider, BitbucketPullRequestApi, BitbucketPullRequestProvider, PullRequestService and PullRequestSyncReactor tests: 6 files, 279 tests passed (re-ran the BitbucketApi, BitbucketSourceControlProvider and PullRequestService files after the follow-up commit: 202 passed).
  • apps/server typecheck passes.
  • Not checked: a running desktop app against a real Data Center remote.

Made with Claude Opus (claude-opus-5-5) in OpenCode (oh-my-opencode).

@github-actions github-actions Bot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Oct 1, 2026
@macroscopeapp

macroscopeapp Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This changes the default behavior of existing self-hosted Bitbucket integrations, suppressing pull-request operations and credential-bearing Cloud API requests unless an explicit API root is configured. The scope is focused and tested, but the default-behavior and request-routing changes warrant human review.

You can add or adjust custom eligibility rules. Learn more.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Important

Review skipped

Review was skipped as selected files did not have any reviewable changes.

⚙️ Run configuration

Configuration used: Repository: pingdotgg/t3code/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 9e782024-4161-4965-a24e-ead7ee29e570

📥 Commits

Reviewing files that changed from the base of the PR and between 5542b87 and 5a1d491.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: pingdotgg/t3code/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 94c6b200-fd79-4f38-bdbf-57c3feefac35

📥 Commits

Reviewing files that changed from the base of the PR and between ceb05fe and 5542b87.

📒 Files selected for processing (2)
  • apps/server/src/sourceControl/BitbucketApi.test.ts
  • apps/server/src/sourceControl/BitbucketApi.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review.


📝 Walkthrough

Walkthrough

Bitbucket remotes on hosts other than bitbucket.org are not treated as addressable by default. Setting T3CODE_BITBUCKET_API_BASE_URL explicitly allows those remotes through the API and pull request listing checks.

Changes

Bitbucket host handling

Layer / File(s) Summary
Gate Bitbucket remote resolution
apps/server/src/sourceControl/BitbucketApi.ts, apps/server/src/sourceControl/BitbucketApi.test.ts
Remote resolution accepts non-Cloud Bitbucket hosts only when the API base URL is explicitly configured. Tests cover rejecting an unconfigured self-hosted remote without an API request and the configured API base URL request path.
Apply host gating to pull request listing
apps/server/src/pullRequest/PullRequestService.ts, apps/server/src/pullRequest/PullRequestService.test.ts
Pull request listing leaves self-hosted Bitbucket projects unsupported when no custom API base URL is configured. Tests cover Cloud and self-hosted projects with and without that setting.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Bug fix · Severity of issue fixed: Medium

Suggested reviewers: juliusmarminge

Merge Risk: ⚪ Minimal · up to 5542b

Self-hosted Bitbucket repositories are skipped or rejected unless an API base URL is explicitly configured, while Bitbucket Cloud remains supported. No actionable merge-blocking risk was identified; merge after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 5542b

The change restricts requests for self-hosted repositories rather than expanding access or credential authority. Explicit API configuration retains the previous routing behavior. No introduced security concern was identified, but complete external caller coverage was not established.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • observed — The affected sensitive sink is the server-configured Bitbucket API, with available credentials attached from server settings or environment configuration. Repository locators select encoded repository paths beneath that API base rather than supplying an outbound HTTP host.

Trust Boundaries and Controls

  • observed — The new controls revalidate remote eligibility inside BitbucketApi and prevent unsupported projects from reaching the listing provider. Both selected contexts and checkout remote scans require Cloud identity or explicit API-base configuration.
  • observed — Explicit repository locators retain their pre-existing precedence over remote validation. This is not a universal prohibition on Cloud calls from a self-hosted checkout, but the inspected path does not introduce a new destination or authority: it builds requests under the configured API base.
  • observed — The unchanged raw-request helper checks absolute URLs against the configured API origin before attaching credentials and rechecks redirect targets through the same helper. This control is separate from the newly added remote-eligibility gate.
🚥 Pre-merge checks | ✅ 3 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Linked Issues check ⚠️ Warning The PR satisfies request 1 in issue #14591. PullRequestService skips unconfigured non-bitbucket.org hosts, and BitbucketApi rejects their remotes before an HTTP request. Tests cover skipped read… Implement the remaining coding requirements from issue #14591, or change the linked issue scope before merging. Add Server/Data Center REST API 1.0 support with access-token authentication and per-host base URLs. Add the per-project PR-sync…
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 4 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (3 passed)
Check name Status Explanation
Out of Scope Changes check ✅ Passed The production changes prevent unconfigured self-hosted Bitbucket remotes from using the Bitbucket Cloud provider. The configuration check, remote validation, and tests directly support request 1 in i…
Title check ✅ Passed The title clearly and concisely describes the primary fix: preventing self-hosted Bitbucket repositories from being sent to the Bitbucket Cloud API.
Description check ✅ Passed The description includes the required Problem, Change, Scope and approval, and Verification sections. It explains expected behavior, links the triaged issue, identifies out-of-scope work, and reports …
Full details: Linked Issues check

Explanation

The PR satisfies request 1 in issue #14591. PullRequestService skips unconfigured non-bitbucket.org hosts, and BitbucketApi rejects their remotes before an HTTP request. Tests cover skipped reads, explicit configuration, named remotes, and request suppression. Issue #14591 also requests Bitbucket Server/Data Center support with REST API 1.0 and access-token authentication, per-host base URLs, and a per-project PR-sync disable setting. The diff does not implement these requirements. The issue's freeze-recovery item is marked nice to have and is not needed for this verdict.

Resolution

Implement the remaining coding requirements from issue #14591, or change the linked issue scope before merging. Add Server/Data Center REST API 1.0 support with access-token authentication and per-host base URLs. Add the per-project PR-sync disable setting. Add automated tests for these behaviors.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@juliusmarminge juliusmarminge added the macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews label Oct 2, 2026 — with ChatGPT Codex Connector

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews size:M 30-99 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list.

Projects

None yet

2 participants