feat(github): use the right account for each repository - #6052
DominicVonk wants to merge 20 commits into
Conversation
|
Important Review skippedAuto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Two findings in apps/server/src/sourceControl/GitHubCli.ts: new validation failures fabricate an Error only to satisfy the required cause field, and the real reason never reaches the error's structural attributes or message.
Posted via Macroscope — Effect Service Conventions
There was a problem hiding this comment.
Effect service conventions review of the changed server/contracts/web TypeScript. The GitHub account-selection code in apps/server/src/sourceControl/GitHubCli.ts carries new failure modes in synthetic new Error(...) causes attached to pre-existing generic error tags, which the conventions disallow. One test-only namespace/deprecation note is included as well.
Posted via Macroscope — Effect Service Conventions
There was a problem hiding this comment.
One error-modelling finding in apps/server/src/sourceControl/GitHubCli.ts: the new gh auth token subprocess failure is collapsed onto GitHubCliAuthenticationError instead of the file's reusable fromVcsError classifier.
Posted via Macroscope — Effect Service Conventions
ApprovabilityVerdict: Needs human review This PR introduces a substantial new feature for multi-account GitHub support with per-owner credential routing. It adds ~1600 lines including new credential selection logic, settings schemas, and UI components, and involves security-sensitive token handling from environment variables and the GitHub CLI keyring. The scope and authentication implications warrant human review. No code changes detected at You can customize Macroscope's approvability policy. Learn more. |
There was a problem hiding this comment.
One convention finding: the new local service dependency is imported by name rather than through its module namespace. Everything else in the account-selection work (dedicated tagged errors with structural fields and no invented causes, yield*-based dependency acquisition in make, subpath namespace imports for effect/*, no new Layer.succeed/ManagedRuntime/runPromise) matches the conventions.
Posted via Macroscope — Effect Service Conventions
b374363 to
fb7da77
Compare
There was a problem hiding this comment.
One convention finding on the new GitHub credential failure model in apps/server/src/sourceControl/GitHubCli.ts. Everything else in the changed Effect service scope (namespace imports, ServerSettings acquisition via the environment, make/layer shape, the pure GitHubCredentials routing helper, and the new tests) looks consistent with the conventions.
Posted via Macroscope — Effect Service Conventions
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit f84749e. Configure here.
|
thanks for the contribution! closing this at the request of @StiensWout because it currently has merge conflicts. if you think closing this was a mistake, please feel free to reopen it. |

What Changed
gh auth status --json hosts.Why
T3 Code previously used whichever GitHub CLI account happened to be active. Users signed into personal, work, or GitHub Enterprise accounts could therefore access a repository with the wrong identity unless they switched accounts outside T3 Code.
Routing by host and repository owner matches how users separate those accounts while keeping GitHub CLI as the token authority.
UI Changes
Previously, the GitHub provider settings did not expose account selection. The updated UI shows each host's default account and lets users add repository-owner overrides.
Checklist
Created with GPT-5.6 Sol in T3 Code.
Note
High Risk
Changes GitHub authentication and credential selection for all CLI/PR operations, including token injection and how viewers/batches are resolved across repositories.
Overview
Lets users pick which signed-in GitHub account T3 Code uses per host, with optional overrides by repository owner, instead of always using the active
ghaccount.Adds
githubAccountRoutingsettings and a Source Control settings UI to choose defaults and owner overrides. Credentials stay with GitHub CLI / env vars; T3 Code only stores login + token source.GitHubClinow resolves a credential route for each call and injectsGH_TOKEN/GH_ENTERPRISE_TOKENaccordingly. Pull request listing and viewer resolution batch by that route so repos on the same host with different accounts stay separate, and involvement filtering can use per-repository viewers.Reviewed by Cursor Bugbot for commit 7620cb2. Bugbot is set up for automated code reviews on this repo. Configure here.
Note
Route GitHub CLI calls using the correct account per repository
GitHubAccountRoutingsettings (default account per host, per-owner overrides) persisted inServerSettingsand editable via a new settings UI in GitHubAccountSettings.tsx.ghkeyring based on the chosen account, then injectsGH_TOKEN/GH_ENTERPRISE_TOKENfor every CLI/GraphQL call.hostandrepositoriesscoping so the right token is used per request.getViewerLogin,getBatchKey, andexecuteinterfaces are extended with requiredhost/repositoryparameters, which is a breaking change for any callers ofGitHubPullRequestCliorGitHubClioutside this PR.Macroscope summarized 7620cb2.