Files
Why_So_SeriousandGitHub e34f546b8c fix(github): restore the recovery path for revoked user OAuth tokens (#10995)
* fix(github): honour the force flag in checkRefreshToken

`checkRefreshToken` accepts a `force` parameter but never reads it, so the
only caller that passes `force = true` (worker.ts, when re-syncing a user)
behaves exactly like the non-forced call and skips the refresh entirely.

Gate the refresh on `force || expired` instead of on expiry alone. As a
side effect a record with a `refreshToken` but a null `expiresIn` is now
validated when forced, instead of being reported as valid unchecked.

Signed-off-by: koreanjoker <namug014@gmail.com>

* fix(github): return undefined from getOctokit when the token is dead

When `checkRefreshToken` reports failure, `getOctokit` cleared
`record.octokit` and then fell straight through to constructing a new
Octokit from the very token that was just rejected. The method therefore
never returned `undefined` for a revoked user, so the
`(await getOctokit(...)) ?? container.container.octokit` installation-token
fallback that the sync code already writes at 13 call sites was
unreachable.

Return `undefined` after clearing the client so the existing fallback can
take effect.

Signed-off-by: koreanjoker <namug014@gmail.com>

* fix(github): preserve accounts when deserialising a user secret

`updateUser` serialises the whole `GithubUserRecord` — `accounts`
included — into the integration secret, but `secretToUserRecord` placed a
literal `accounts: {}` after the spread of the parsed payload, discarding
whatever was stored.

Every consumer of a record loaded through `getAccount` therefore saw an
empty map. `revokeUserAuth` iterates `Object.entries(record.accounts)`, so
its body never ran and the re-authorisation notice was never written to
any workspace.

Read `accounts` back from the parsed payload, keeping `{}` as the fallback
for records written before the field existed.

Signed-off-by: koreanjoker <namug014@gmail.com>

---------

Signed-off-by: koreanjoker <namug014@gmail.com>
2026-07-27 00:11:38 +07:00
..
2024-07-28 14:55:43 +07:00
2024-07-28 14:55:43 +07:00
2024-07-28 14:55:43 +07:00
2024-07-28 14:55:43 +07:00
2025-09-16 23:18:12 +07:00
2024-07-28 14:55:43 +07:00

Github App guidelines

https://github.com/github/github-app-js-sample/tree/main

Developer resources

Forward github events to platform

  smee -u https://smee.io/Oj0ZkULovroxbFC6 -t http://localhost:3500/api/webhook

Shared application should be linked via https://github.com/apps/<app name>/installations/new?state=AB12t

https://docs.github.com/en/apps/sharing-github-apps/sharing-your-github-app

Instructions to setup GitHub integration for local testing

Register a new GitHub App

Go to Settings/Developer settings/GitHub Apps

New webhook

Go to https://smee.io/ and click Start a new channel

  • Use the provided Webhook Proxy URL as Webhook URL. Referred as WEBHOOK_URL later in the document.
  • Webhook secret is: secret
  • Keep Webhook Active checked.

Configure permissions for the app:

  • Commit statuses: Read and write
  • Contents: Read and write
  • Custom properties: Read and write
  • Discussions: Read and write
  • Issues: Read and write
  • Metadata: Read-only
  • Pages: Read and write
  • Projects: Read and write
  • Pull requests: Read and write
  • Webhooks: Read and write

Subscribe to events:

  • Issues
  • Pull request
  • Pull request review
  • Pull request review comment
  • Pull request review thread

Final creation steps

  • Create the app.
  • Generate a new client secret. Referred as POD_GITHUB_CLIENT_SECRET later in the document.
  • Create and download you private key file as well. Referred as POD_GITHUB_PRIVATE_KEY later in the document.
  • You'll be provided with your GitHub app ID. Referred as POD_GITHUB_APPID later in the document.

Forward webhook events to local server

  • Install smee client:
npm install --global smee-client
  • To forward events (keep it up and running):
smee -u {WEBHOOK_URL} -t http://localhost:3500/api/webhook

Update local config files

.vscode/launch.json —> Debug Github integration
  • "APP_ID": "{POD_GITHUB_APPID}" <— Numeric ID of the new application
  • "CLIENT_ID": "{POD_GITHUB_CLIENTID}" <—- Client ID from the new application
  • "CLIENT_SECRET": "{POD_GITHUB_CLIENT_SECRET}" <—- Client Secret from the new application
  • "PRIVATE_KEY": "{POD_GITHUB_PRIVATE_KEY}" <—- PK from the new application

Note: PK value format: "-----BEGIN RSA PRIVATE KEY-----\n {ACTUAL_KEY_WO_LINE_BREAKS}\n-----END RSA PRIVATE KEY-----

dev/prod/public/config.json
  • "GITHUB_APP": “{GITHUB_APP}" <— Textual name of the new application
  • "GITHUB_CLIENTID": “{POD_GITHUB_CLIENTID}” <— Client ID from the new application

Usage

  • Run dev GitHub pod (Debug Github integration) in vscode
  • Run dev server
  • On localhost:8080 Go to Settings -> Integrations -> Github
    • On the first tab authorise your GitHub
    • On the second tab of the dialog install the application, select a GH repo and connect to an existing/create a new connected repo in the tracker.
  • Enjoy!

Note: If the application is already installed in GitHub, make any change e.g. switch between "All repositories" and "Only select repositories" and click "Save".