Skip to content

fix(server): a bare repository name resolves to the signed-in account again - #17379

Open
ScottN-PV wants to merge 1 commit into
pingdotgg:mainfrom
ScottN-PV:fix/17230-bare-repo-name
Open

ScottN-PV wants to merge 1 commit into
pingdotgg:mainfrom
ScottN-PV:fix/17230-bare-repo-name

Conversation

@ScottN-PV

@ScottN-PV ScottN-PV commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Problem

Since GitHub lookups moved from gh repo view to the GitHub API (#16321), typing a bare name such as t3code in Add project → GitHub repository fails before any request. getRepositoryCloneUrls accepts owner/name, host/owner/name, or a URL and rejects a single segment. gh read a bare name as the signed-in account's repository.

Change

getRepositoryCloneUrls now reads a single-segment name (no slash or whitespace, .git stripped) as the signed-in account's repository on the host the lookup already resolves for owner/name. It asks GitHub for the viewer's login on that host, then looks up <login>/<name>. Malformed names (me/, /notes, a/b/c/d, two words, empty) are still refused before any request. This is the first bare-name viewer lookup in the provider. createRepository posts a bare name to user/repos without one.

Scope and approval

Refs #17230. The triage comment confirms the bare-name regression from #16321 and treats the generic error message as a separate question. That half is unchanged here, so other lookup failures still show the generic toast. #8300 would reject bare names in the service layer. #15969 allows them client-side and does not conflict.

Verification

An agent ran these checks. No person tested the change.

Dev app (vp run dev) on Windows with the signed-in gh account, Add project → GitHub repository → t3code:

Before (main) After
Before: Repository lookup failed After: resolves to ScottN-PV/t3code

After the change, the lookup resolves to ScottN-PV/t3code and stops at the clone confirmation. Nothing was cloned.

  • New test in GitHubSourceControlProvider.test.ts: on a GitHub Enterprise host from the repository context, notes.git reads the viewer and then repos/me/notes on that host and returns its clone URLs. me/, /notes, a/b/c/d, empty, and two words are refused with no request. The test fails on main with "Repositories are named owner/name."
  • After rebasing onto refactor(source-control): GitHub lives in @t3tools/source-control-github #17607, which moved the provider to packages/source-control-github: vp test run src/server/GitHubSourceControlProvider.test.ts there passes 42 tests, and the new test still fails without the fix. Package typecheck, vp lint, and vp fmt --check on the two changed files pass.

Model: Claude Opus 5.5, Claude Fable 5.1 (review), GPT-6-Astra (review). Harness: Claude Code, Codex.

@github-actions github-actions Bot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:XS 0-9 changed lines (additions + deletions). labels Oct 9, 2026
@macroscopeapp

macroscopeapp Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at ff3fdf3

Macroscope's review found this PR approvable — This narrowly restores bare GitHub repository-name resolution to the signed-in account, with existing selector behavior preserved and focused tests covering Enterprise hosts, normalization, and invalid inputs. The only new runtime work is the viewer lookup required for this newly valid input form.

You can add or adjust custom eligibility rules. Learn more.

@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Path: .coderabbit.config.ts
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 7fa3d6a0-094d-4618-ac00-29659f3c3001

📥 Commits

Reviewing files that changed from the base of the PR and between ff3fdf3 and 257968d.


📒 Files selected for processing (2)
  • packages/source-control-github/src/server/GitHubSourceControlProvider.test.ts
  • packages/source-control-github/src/server/GitHubSourceControlProvider.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.



📝 Walkthrough

Walkthrough

getRepositoryCloneUrls now resolves a bare repository name under the signed-in user on the fallback host. Tests verify host-specific clone URLs and rejection of malformed names.

Changes

Bare Repository Name Lookup

Layer / File(s) Summary
Resolve and test bare repository names
packages/source-control-github/src/server/GitHubSourceControlProvider.ts, packages/source-control-github/src/server/GitHubSourceControlProvider.test.ts
The provider trims the input and removes a trailing .git when detecting a bare name. It uses the signed-in user as the owner and retains the existing error path for other unparsed inputs. Tests cover host-specific clone URLs and malformed names.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Suggested reviewers: juliusmarminge


Merge Risk

Merge Risk: ⚪ Minimal · up to 25796

Bare repository names now resolve to the signed-in account again, and malformed names are still rejected. No merge-blocking risk is evident.

Security Architecture Review

Security architecture risk: ⚪ Minimal · up to 25796

Bare-name lookup uses the existing host and credential controls and only reads account and repository information. The reviewed change does not introduce broader permissions, a new host-selection mechanism, or persistent state changes.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The added lookup is confined to the previously selected GitHub host and repositories readable by credentials obtained for that host. A bare repository name does not supply a new host or grant additional GitHub permissions; the additional exposure is one viewer read before the existing repository read.

Trust Boundaries and Controls

  • observed — The existing API layer resolves credentials by normalized host and adds bearer authorization inside its transport. Pinned credentials reject a different host, disabled hosts are refused, and enterprise environment tokens are restricted to the configured GH_HOST. The new viewer read uses this same layer.

Resilience and Maintainability Implications

  • observed — The additional viewer request inherits the existing quota admission, rate-limit checks, response-size bound, and request deadline. It does not introduce an alternate unbounded HTTP path.



Pre-merge checks | Passed 4
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.
Title check Passed The title clearly and concisely describes the primary change: bare GitHub repository names now resolve to the signed-in account.
Description check Passed The description includes all required sections. It explains the regression, implementation, scope approval, malformed-input behavior, test coverage, manual verification, limitations, and agent details…


✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR


  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

… again

Since lookups moved from gh repo view to the GitHub API, a bare name such
as "notes" failed with "Repositories are named owner/name." before any
request. gh read it as the signed-in account's repository; the lookup now
does the same on the repository's host.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ScottN-PV
ScottN-PV force-pushed the fix/17230-bare-repo-name branch from ff3fdf3 to 257968d Compare October 9, 2026 21:55

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS 0-9 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant