Setup wizard: create-token link with the right scopes pre-checked (RT-276) - #433
Merged
Merged
Conversation
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…nk (RT-276) Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ed, naming them (RT-276) Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…wns forge scopes Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
|
Warning Review limit reachedNext included review available in 4 minutes. View limit detailsLimit details: You’ve used the included review currently available. Your 83 included PR review attempts over the past 7 days set your current allowance at 1 review per hour. Your organization has reached its usage spending cap. Adjust your spending cap in the billing tab. Review configuration: ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (17)
Comment |
…nstall; unconfirmed hosts get no link; stored tokens checked too (RT-276 review) Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…iew) Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Setup wizard: one-click "create a token" link with the right scopes pre-checked
RT-276. A new teammate connecting GitHub or GitLab gets a link in the Connect sheet that opens the forge's new-token page with rt's scopes already checked and the token named
mattstack. The scope lists now come from GitLab's own ability table:read_apialready carries git clone, so a member's hint staysread_api, read_user, while an owner (home-repo push,rt team members sync) needsapi, which the old hint never asked for.What changed
Scopes (
lib/setup/token-create.ts)read_api, read_user. GitLab owner:api. GitHub:repo, read:org(classic; the kind whose scopes the validator can read).forgeRole: create intent is the owner, join intent a member; once Install has cleared the intent, the team-local record decides (a clone rt joined is a member's, any other team the owner's).missingScopeshonors containment (apicoversread_api,admin:orgcoversread:org) and treats an empty scope report (fine-grained GitHub) as no shortfall.Contract and rows
connectactions gain an optionalcreate: { label, url }. The link names only a host the user confirmed or the provider's own; a team-declared self-hosted name gets no link untilconnect --hostconfirms it, the same standing the token waits for.invalidon the row withtoken is missing: apiand the create link.rt setup <forge> connectrefuses such a token before storing it; on the--use-ghpath the detail adds thegh auth refresh -s <scope>command.Tray
ActionLinkonRowAction;collectFieldscarries it; the dispatcher drops anything but https before the sheet sees it.ConnectSheetshows "Create a token on GitLab…" above the paste field and opens the browser without closing.Also
createfield and thattoken-create.tsis the one place a scope is added.Follow-up
/-/user_settings/personal_access_tokens, the route since 16.x; an older self-hosted instance 404s on it.Verification
bun run testgreen before the review fixes, re-run after.swift buildgreen.🤖 Generated with Claude Code