Repository navigation
fix(server): stop sending self-hosted Bitbucket repositories to Bitbucket Cloud - #14593
BerkayClik wants to merge 3 commits into
Conversation
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This changes the default behavior of existing self-hosted Bitbucket integrations, suppressing pull-request operations and credential-bearing Cloud API requests unless an explicit API root is configured. The scope is focused and tested, but the default-behavior and request-routing changes warrant human review. You can add or adjust custom eligibility rules. Learn more. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Important Review skippedReview was skipped as selected files did not have any reviewable changes. ⚙️ Run configurationConfiguration used: Repository: pingdotgg/t3code/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: pingdotgg/t3code/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review. 📝 WalkthroughWalkthroughBitbucket remotes on hosts other than ChangesBitbucket host handling
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix · Severity of issue fixed: Medium Suggested reviewers: Merge Risk: ⚪ Minimal · up to Self-hosted Bitbucket repositories are skipped or rejected unless an API base URL is explicitly configured, while Bitbucket Cloud remains supported. No actionable merge-blocking risk was identified; merge after normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change restricts requests for self-hosted repositories rather than expanding access or credential authority. Explicit API configuration retains the previous routing behavior. No introduced security concern was identified, but complete external caller coverage was not established. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
🚥 Pre-merge checks | ✅ 3 | ❌ 2❌ Failed checks (2 warnings)
✅ Passed checks (3 passed)
Full details: Linked Issues checkExplanation The PR satisfies request 1 in issue Resolution Implement the remaining coding requirements from issue ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
…ack to a Cloud remote
Problem
A remote on a self-hosted Bitbucket Server / Data Center host (e.g.
https://bitbucket.example.com/scm/<project>/<repo>.git) is classified asbitbucket, but the Bitbucket client only speaks Bitbucket Cloud. So the pull-request sync sweep, the pull-request browser, branch PR status and PR creation all send requests (with any configured Cloud credentials) toapi.bitbucket.orgfor a repository that lives on another server. The reporter saw thousands of these requests in their traces.Fixes #14591.
Change
As proposed in the triage: don't call the Cloud API for a host other than
bitbucket.orgunless a Cloud base URL was explicitly configured (T3CODE_BITBUCKET_API_BASE_URL).PullRequestService.listWorkspaceProjects: such a Bitbucket host gets no implementation, so it goes down the existing unimplemented-host path ("This host cannot be browsed here yet."). PR sync and the browser no longer read it.BitbucketApi.resolveRepository: such a remote is not resolved, so branch status, PR creation and checkout fail withBitbucketRepositoryRemoteNotFoundErrorbefore any request goes out. A named Bitbucket context that is rejected fails outright instead of falling back to another (Cloud) remote in the same checkout, so a mixed-remote checkout can't have the operation land on a different repository.BitbucketApiBaseUrlConfiguredconfig, so the escape hatch stays defined in one place.bitbucket.orgbehavior is unchanged. Bitbucket Server / Data Center support itself is out of scope; it's tracked in #10837.Scope and approval
Triaged bug with the intended behavior spelled out in the triage comment: #14591 (comment) ("don't call the Cloud API for any host other than
bitbucket.orgunless a Cloud base URL was explicitly configured. Those checkouts should be marked unsupported for pull-request sync and the pull-request browser.")Verification
PullRequestService.test.ts: abitbucket.example.comproject is listed as an unconfigured host and its provider is never asked, while abitbucket.orgproject next to it still is. WithT3CODE_BITBUCKET_API_BASE_URLset, the self-hosted project is read again.BitbucketApi.test.ts:listPullRequestsfor a self-hosted remote fails withBitbucketRepositoryRemoteNotFoundErrorand makes no HTTP call. With the base URL set, it requests<base>/repositories/proj/repo/pullrequestsas before. A self-hosted context in a checkout that also has abitbucket.orgremote fails the same way, with no HTTP call.vp test runonBitbucketApi,BitbucketSourceControlProvider,BitbucketPullRequestApi,BitbucketPullRequestProvider,PullRequestServiceandPullRequestSyncReactortests: 6 files, 279 tests passed (re-ran theBitbucketApi,BitbucketSourceControlProviderandPullRequestServicefiles after the follow-up commit: 202 passed).apps/servertypecheck passes.Made with Claude Opus (claude-opus-5-5) in OpenCode (oh-my-opencode).