Skip to content

Setup wizard: create-token link with the right scopes pre-checked (RT-276) - #433

Merged
m4ttheweric merged 7 commits into
mainfrom
rt-pat-create-link
Sep 25, 2026
Merged

m4ttheweric merged 7 commits into
mainfrom
rt-pat-create-link

Conversation

@m4ttheweric

@m4ttheweric m4ttheweric commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

Setup wizard: one-click "create a token" link with the right scopes pre-checked

RT-276. A new teammate connecting GitHub or GitLab gets a link in the Connect sheet that opens the forge's new-token page with rt's scopes already checked and the token named mattstack. The scope lists now come from GitLab's own ability table: read_api already carries git clone, so a member's hint stays read_api, read_user, while an owner (home-repo push, rt team members sync) needs api, which the old hint never asked for.

What changed

Scopes (lib/setup/token-create.ts)

  • One list per forge and role feeds the field hint, the create link and the scope check.
  • GitLab member: read_api, read_user. GitLab owner: api. GitHub: repo, read:org (classic; the kind whose scopes the validator can read).
  • forgeRole: create intent is the owner, join intent a member; once Install has cleared the intent, the team-local record decides (a clone rt joined is a member's, any other team the owner's).
  • missingScopes honors containment (api covers read_api, admin:org covers read:org) and treats an empty scope report (fine-grained GitHub) as no shortfall.

Contract and rows

  • connect actions gain an optional create: { label, url }. The link names only a host the user confirmed or the provider's own; a team-declared self-hosted name gets no link until connect --host confirms it, the same standing the token waits for.
  • A stored token the forge accepts but that lacks the role's scopes reads invalid on the row with token is missing: api and the create link.
  • rt setup <forge> connect refuses such a token before storing it; on the --use-gh path the detail adds the gh auth refresh -s <scope> command.

Tray

  • ActionLink on RowAction; collectFields carries it; the dispatcher drops anything but https before the sheet sees it.
  • ConnectSheet shows "Create a token on GitLab…" above the paste field and opens the browser without closing.
  • Stub-rt fixture carries the link so the walkthrough shows it.

Also

  • AGENTS.md notes the create field and that token-create.ts is the one place a scope is added.

Follow-up

  • The GitLab link uses /-/user_settings/personal_access_tokens, the route since 16.x; an older self-hosted instance 404s on it.

Verification

  • 13 unit tests for the scope module, 6 for the connect refusal, 7 new row cases; full bun run test green before the review fixes, re-run after.
  • Swift checks 382/382 (incl. the https guard); full swift build green.
  • Opus substitute review (CodeRabbit rate-limited): 9 findings, 8 addressed, the 16.x route accepted as a follow-up.
  • The rendered sheet was not looked at (skipped by request).

🤖 Generated with Claude Code

m4ttheweric and others added 5 commits September 24, 2026 18:58
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…nk (RT-276)

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ed, naming them (RT-276)

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…wns forge scopes

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 4 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available. Your 83 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Your organization has reached its usage spending cap. Adjust your spending cap in the billing tab.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 6464b1ad-a1d4-423f-b312-0a1c11f23288

📥 Commits

Reviewing files that changed from the base of the PR and between b983acc and bb1390c.

📒 Files selected for processing (17)
  • AGENTS.md
  • commands/__tests__/setup-connect.test.ts
  • commands/setup.ts
  • lib/setup/__tests__/token-create.test.ts
  • lib/setup/__tests__/validators-accounts.test.ts
  • lib/setup/contract.ts
  • lib/setup/integrations.ts
  • lib/setup/token-create.ts
  • lib/setup/validators/accounts.ts
  • rt-tray/Sources-core/Contract/PlanModels.swift
  • rt-tray/Sources-core/Readiness/RowActionDispatcher.swift
  • rt-tray/Sources/AccessibilityIDs.swift
  • rt-tray/Sources/Setup/Components/ConnectSheet.swift
  • rt-tray/Sources/Setup/Screens/ChecklistScreen.swift
  • rt-tray/Tests/MattstackCoreChecks/PlanModelsChecks.swift
  • rt-tray/Tests/MattstackCoreChecks/RowActionChecks.swift
  • rt-tray/Tests/stub-rt/stub.ts

Comment @coderabbitai help to get the list of available commands.

m4ttheweric and others added 2 commits September 24, 2026 19:23
…nstall; unconfirmed hosts get no link; stored tokens checked too (RT-276 review)

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…iew)

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@m4ttheweric
m4ttheweric merged commit 5b7ef33 into main Sep 25, 2026
6 checks passed
@m4ttheweric
m4ttheweric deleted the rt-pat-create-link branch September 25, 2026 00:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant