Repository navigation
gh auth ignores the http_unix_socket config value #11891
Description
Activity
Hi @drevell! Thanks for reporting and making a PR for it! 🍻
I looked into the internals of how
ghinstantiates HTTP clients, and I can confirm what you're seeing as a bug. As I checked, only theauth logincommand is affected and other commands should work as expected.Regarding the PR, while I appreciate your time for making it, I'm going to close it as it's duplicating the code in
cli/go-gh, which is a base module used byghand extensions that takes care of fundamental/cross-cutting concerns.I'm working on a fix for this issue, but in the meantime I need to know if the PR you made resolves your issue with
auth login.Also, I don't know how things are set up at your end, but since you mentioned proxy, I'm curious to know if you have tried setting
HTTPS_PROXYenv var. Sorry, if that's inapplicable to your use case, but I'm asking in case there's already a solution to unblock you.Reacted by Dave RevellReacted by Saurav Chawla- addedpriority-2Affects more than a few users but doesn't prevent core functionsAffects more than a few users but doesn't prevent core functionsgh-authrelating to the gh auth commandrelating to the gh auth commandand removedneeds-triageneeds to be reviewedneeds to be reviewed
on Oct 10, 2025 Thank you Babak, I understand that it doesn't make sense to use my PR when there's existing logic in a library for this. Thanks for taking the time to understand what's going on.
Thanks for the suggestion of HTTPS_PROXY. For our particular use case, we really want to use the http_unix_socket rather than HTTPS_PROXY (we're certainly aware of that option). The reasons are obscure and corporate and have to do with the limitations of the quirky proxy we're required to use.
Reacted by Babak K. Shandiz- linked a pull request that will close this issueFix `auth login` and `auth refresh` to use UNIX socket #11922
on Oct 13, 2025 @drevell I've just submitted a PR for this. While it's waiting for review, can you please clone the PR branch, build from source, and verify it fixes the issue?
I've already added the steps to verify the behaviour, but since you already have a working setup, I think you wouldn't need it. However, you can go through the same commands/experiences to make sure all is okay.
Reacted by Dave RevellReacted by Saurav Chawla and Dave RevellThe fix works for me. The bug was preventing us from using the OAuth "device flow." With the fix, it now works.
$ gh auth login ? What is your preferred protocol for Git operations on this host? SSH ? Upload your SSH public key to your GitHub account? Skip ? How would you like to authenticate GitHub CLI? Login with a web browser ! First copy your one-time code: <redacted> Press Enter to open https://<redacted>/login/device in your browser... [<redacted>] Missing X server or $DISPLAY [<redacted>] The platform failed to initialize. Exiting. ...<at this point I copy-paste the above URL into my browser and complete the login flow>... ✓ Authentication complete. - gh config set -h <redacted> git_protocol ssh ✓ Configured git protocol ! Authentication credentials saved in plain text ✓ Logged in as revell ! You were already logged in to this accountReacted by Babak K. Shandiz and Kynan WareThe changes will be shipped in the upcoming release.
Reacted by Dave Revell
Describe the bug
gh has an option "http_unix_socket" that should route HTTP requests through the provided unix domain socket. In some places, that option is ignored where it should be used.
Fix PR
I sent you a PR with an attempted fix in #11890
Affected version
2.80.0
Steps to reproduce the behavior
Run gh auth login with the
http_unix_socketoption set, and watch it be ignored for outgoing HTTP requests.Expected vs actual behavior
Device flow authentication should be possible when using http_unix_socket. gh should not bypass the socket and make HTTP requests directly (should not bypass the proxy).
Logs
Paste the activity from your command line. Redact if needed.