Skip to content

Internal git pull/push operations are not always authenticated #2944

Description

@mislav

The HTTPS credential behavior introduced in #2449 is only effective after the user has completed the interactive gh auth login flow. However, if someone does this in a script:

GH_TOKEN="..." gh repo clone <repo>

The internal git clone operation is not guaranteed to use the supplied token. Instead, the usual git credential mechanism is used, so if this was run in an isolated environment such as a CI job, the clone command would most likely fail on prompting for username+password.

Commands that can currently result in a git network operation:

  • repo clone - git clone
  • repo fork - git remote add -f
  • pr create - git remote add -f, git push

We could try to add extra flags to those invocations of git to configure that gh should be used unconditionally as a credential helper. Something like:

git -c 'credential.helper=' \
    -c 'credential.https://<GH_HOST>.helper=' \
    -c 'credential.helper=!gh auth git-credential' \
    clone ...

Activity

  1. added
    coreThis issue is not accepting PRs from outside contributors
    on Feb 16, 2021
  2. added
    priority-1Affects a large population and inhibits work
    on Nov 8, 2021
  3. ItsHarper commented on Jan 7, 2022

    @ItsHarper

    If you are facing this issue from a GitHub Actions workflow, running gh auth setup-git is a good workaround.

  4. added
    priority-2Affects more than a few users but doesn't prevent core functions
    and removed
    priority-1Affects a large population and inhibits work
    on Mar 28, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingcoreThis issue is not accepting PRs from outside contributorspriority-2Affects more than a few users but doesn't prevent core functions

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions