Skip to content

Document the relationship between hosts and active accounts #9021

Description

@danfbfern

Describe the bug

Have two different accounts, one is my personal one and the other its from from github enterprise.
I'm able to push, commit, etc with both my accounts but apparently I have been committing to the enterprise with my personal one because both of the accounts are shown as active, and the gh auth switch doesn't do anything.

For context, I have two different SSH keys and used each one to configure the gh cli but was expecting to have one as active and the other to not be active.
Tried doing it all over again, with HTTPS instead with no luck

I'm using gh version 2.48.0

Steps to reproduce the behavior

  1. Add multiple accounts
  2. check gh auth status to see if both are active at the same time

Expected vs actual behavior

image

I expected to one account with active on true and the other on false

Activity

  1. williammartin commented on Apr 29, 2024

    @williammartin
    Member

    Hey @danfbfern, sorry you're running into issues. I think there's a bit of confusion here and as such I'm not really sure what to make of your bug report.

    The CLI and Hosts

    The CLI only targets one host at a time for any invocation. If you are authenticated with two hosts, it will default to targeting github.com. If you are authenticated with only one host, it will target that host. If you are authenticated with zero hosts, it will target github.com. You can change the targeted host by setting the GH_HOST environment variable (more details can be found in gh environment).

    Therefore, it is correct that you have 2 active accounts (1 per host). If you had 2 accounts on a single host then one would be active and one would be inactive.

    So what are you seeing?

    You said:

    I'm able to push, commit, etc with both my accounts but apparently I have been committing to the enterprise with my personal one because both of the accounts are shown as active, and the gh auth switch doesn't do anything.

    Let's take gh out of the picture altogether for a second. If your accounts live on different hosts, you cannot commit to one as the other (I assume by commit you mean push a git commit). Can you provide some more information about what you're actually seeing, preferably with some output copied from your terminal?

    Cheers.

  2. added
    more-info-neededMore info needed from user/contributor
    and removed on Apr 29, 2024
  3. danfbfern commented on Apr 29, 2024

    @danfbfern
    Author

    Hey @williammartin

    Regarding the first part related to hosts, if both arre active because one is enterprise and the other is from github.com, then how do I know im using the right account to commit and push code (both things related to my company and personal stuff)?

    About your question, in a company repo (from github enterprise) I have access to it from my enterprise credentials but whenever I'm commiting and pushing code, its showing up with my personal user instead.
    image

    Shouldn't I be able to choose my account and if the active one was the personal then I wouldn't be able to commit to it?

  4. williammartin commented on Apr 29, 2024

    @williammartin
    Member

    Regarding the first part related to hosts, if both arre active because one is enterprise and the other is from github.com, then how do I know im using the right account to commit and push code (both things related to my company and personal stuff)?

    There's a few answers to this but remember at it's core that credentials for an account on one host cannot be used to authenticate with another host.

    but whenever I'm commiting and pushing code, its showing up with my personal user instead.

    Now I think I understand what you mean! The git log in your screenshot shows the git commit objects which has metadata about the git commit including your user.name and user.email. When you git commit, git pulls information from your git config to fill in the commit details. You can look into your git config with information from here. These details are totally unrelated to your GitHub accounts, you could put anything in here you like:

    ➜  git config user.name "Mona Lisa"
    
    ➜  git config user.email "[email protected]"
    
    ➜  git commit --allow-empty
    [main f626508] Mona
    
    ➜  test-repo git:(main) ✗ git log | cat
    commit f626508e6800955293ad90a236c88bcfd6d90e24
    Author: Mona Lisa <[email protected]>
    Date:   Mon Apr 29 19:36:55 2024 +0200
    
        Mona
    

    And gh doesn't currently try to do anything with your user.name and user.email.

    You may find some ways to use IncludeIf to change your git config depending on the targeted remote in #326 but that's totally outside the realm of gh right now.

  5. babakks commented on Apr 29, 2024

    @babakks
    Member

    To add to @williammartin's explanation, I think you can modify your ~/.gitconfig file to apply different user.name and user.email based on the directory where your clone resides. For example if you have something like this in your .gitconfig file:

    [user]
            name = Mona Lisa
            email = [email protected]
    [includeIf "gitdir:~/company/"]
            name = Employee 47
            email = [email protected]

    This instructs git (not gh CLI), to use a different name/email when the repo is under ~/company directory.

  6. danfbfern commented on Apr 30, 2024

    @danfbfern
    Author

    Ohhh thats unfortunate, I though that gh would handle already with the recently added gh auth switch.

    From the documentation its not really clear that gh auth switch would have multiple accounts as active from different hosts, especially given the examples.
    https://cli.github.com/manual/gh_auth_switch

    It looks like it possible to change from an account on a host to another account on a totally different host, meaning that only one of them would be active.

    The solution to use the includeIf is kinda of a workaround because that forces me to separate work directories with personal directories instead of separating by type of repo which is something I'm used to it, making a need to put everything inside that directory, but its acceptable for now

  7. williammartin commented on Apr 30, 2024

    @williammartin
    Member

    Since I wrote the documentation for and implemented auth switch, it's hard for me to see it through any other lens so I'd greatly appreciate if you had some suggestions that would have made the documentation clearer for you!

  8. danfbfern commented on Apr 30, 2024

    @danfbfern
    Author

    Sure thing, that makes sense.

    If the specified host has two accounts, the active account will be switched automatically. If there are more than two accounts, disambiguation will be required either through the --user flag or an interactive prompt.

    Using this quote, it leads to believe that there will be only one active account but it does mention on a specific host, which explains with I have one active in each host.

    But the follow up examples (the last one especially) may lead me back to thinking that I could switch from an account on a specific host to another account on another host, making that one active.

    # Switch to a specific host and specific account
    $ gh auth switch --hostname enterprise.internal --user monalisa
    
  9. williammartin commented on Apr 30, 2024

    @williammartin
    Member

    If we reworded:

    Switch to a specific host and specific account

    To

    Switch the active account on a specific host to a specific user

    Would that have been clearer?

  10. danfbfern commented on Apr 30, 2024

    @danfbfern
    Author

    Yes that would help, and I would personally add a line before the examples and maybe in the gh auth status doc also, to clarify that each host will always have one active account.

    Something like:

    For environments with multiple hosts, the gh auth supports having one active account per host simultaneously. Thus, if you authenticate with different accounts on separate hosts, each account will remain active.

  11. babakks commented on Apr 30, 2024

    @babakks
    Member

    @danfbfern If you don't have personal and work-related repos in separate directories, I think you can use a different condition like this in your .gitconfig file:

    [includeIf "hasconfig:remote.*.url:**/company/**"]
            name = Employee 47
            email = [email protected]

    Or if that didn't work, this:

    [includeIf "hasconfig:remote.*.url:https://github.com/company/**"]
            name = Employee 47
            email = [email protected]

    See here for more about the hasconfig:remote.*.url condition.

  12. danfbfern commented on Apr 30, 2024

    @danfbfern
    Author

    Thanks @babakks
    Didn't knew about that option, I'll try that because it seems like a better approach for my case

  13. changed the title [-]All accounts are active[/-] [+]Document the relationship between hosts and active accounts[/+] on May 1, 2024
  14. added
    gh-authrelating to the gh auth command
    coreThis issue is not accepting PRs from outside contributors
    and removed
    bugSomething isn't working
    more-info-neededMore info needed from user/contributor
    on May 1, 2024
  15. williammartin commented on May 1, 2024

    @williammartin
    Member

    Having added documentation in #9032 to address the confusion, you having a workaround, and there already being work tracking the user.name and user.email features, I'm closing this. Thanks everyone for your involvement.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    coreThis issue is not accepting PRs from outside contributorsdocsgh-authrelating to the gh auth command

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions