Skip to content

Organization-scoped GitHub sign-in inside a work Environment (OAuth, no PAT) #19

Description

@immakermatty

Need

The GitHub sign-in that people complete inside a work Environment (today gh auth login with the GitHub CLI OAuth app) should reach only the Organizations of that Environment. It should still be an OAuth or device-flow sign-in in the person's browser, without personal access tokens and without copying any token.

Why

Root decision 0192 lets the assignee of an individual work Environment share it fully with a trusted member of the same Organization; everything available inside is shared, including signed-in accounts. A GitHub CLI token reaches every Organization the person belongs to, so a full share can expose other Organizations' repositories. Today the rule is that such an Environment is shared fully only with an active member of each involved Organization, and the sharing text explains the broader reach. A sign-in scoped to the Environment's Organizations removes most of that risk.

What is known

  • GitHub CLI tokens come from an OAuth App and are not limited to one Organization; an Organization can only block or allow the whole OAuth App.
  • A GitHub App user access token (device flow supported) is limited to the app's permissions, the user's permissions and the installations of that app. One shared app installed in many Organizations therefore still reaches all of them.
  • Fine-grained PATs can target one resource owner, but PATs are explicitly not wanted.

To decide

Compare at least: a GitHub App per Organization used only for this sign-in; the existing per-Organization broker pattern (attribution and approval constraints for human work); Organization-level OAuth App access restrictions; and how gh/git credential helpers consume the chosen token. Recommend one option to the Operator before implementation.

Planned in Mission Control as DEV-6638 task-2026-10-06-703.

🤖 Generated with Claude Code

Activity

  1. immakermatty commented on Oct 7, 2026

    @immakermatty
    ContributorAuthor

    Findings (2026-10-07):

    • The GitHub CLI token is account-wide (repo, read:org, gist, plus
      admin:public_key when an SSH key is linked). GitHub CLI is a privileged OAuth
      app, so Organization OAuth app access restrictions do not apply to it at all.
    • Lazurio for GitHub is one shared GitHub App installed per Organization; what is
      per Organization is the broker deployment. A user access token of that app would
      reach every Organization where it is installed. Narrowing it to one Organization
      (POST /applications/{client_id}/token/scoped) needs the app's client secret, and
      the unscoped refresh token would have to be stored server side.
    • A private GitHub App owned by an Organization can be installed only on that
      Organization, and only its members can authorize it. Its user access tokens are
      limited to that installation. The device flow works with the public client id
      alone, and device-flow tokens refresh without the client secret.
    • No SSH user key can be limited to one Organization on GitHub Free or Team; SSH CA
      certificates require Enterprise Cloud.

    Proposal for the Operator's decision:

    • Each Organization owns one private sign-in app, used only for device-flow sign-in in
      work Environments.
    • A thin adapter selects the token by repository owner for gh (GH_TOKEN per
      command) and for Git (a credential helper with useHttpPath).
    • Work Environments use HTTPS instead of an account SSH key.
    • Lazurio for GitHub, the brokers and Team Environments are unchanged.

    Sources: GitHub docs on privileged OAuth apps, user access tokens, refreshing user access tokens, public or private apps, scoped access token and SSH certificate authorities. This corrects the issue text above: an Organization cannot block GitHub CLI at all.

    Nothing is implemented yet; the direction awaits the founder's decision. The mechanism itself would live in the Lazurio Platform (sign-in, token store, gh/Git adapter); this repository would only document that Lazurio for GitHub stays the machine and Team identity.

    🤖 Generated with Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions