Skip to content

Add global --account flag for per-invocation user override - #13091

Closed
cataggar wants to merge 1 commit into
cli:trunkfrom
cataggar:cataggar/user-flag
Closed

cataggar wants to merge 1 commit into
cli:trunkfrom
cataggar:cataggar/user-flag

Conversation

@cataggar

@cataggar cataggar commented Apr 3, 2026

Copy link
Copy Markdown

Summary

Adds a global --account persistent flag that overrides the active GitHub account for a single command invocation, eliminating the error-prone switch -> command -> switch back pattern.

Usage

gh issue create --repo myorg/repo --account personal-account
gh pr list --repo corp/repo --account work-account

Changes

  • internal/gh/gh.go: Added SetActiveUser(user string) to the AuthConfig interface
  • internal/config/config.go:
    • Added activeUserOverride field to AuthConfig struct
    • Modified ActiveUser() to check override before config lookup
    • Modified ActiveToken() to use overridden user's token via TokenForUser
    • Added SetActiveUser() method
  • pkg/cmd/root/root.go: Added --account persistent flag, wired in PersistentPreRunE before auth check
  • internal/config/auth_config_test.go: 5 new unit tests covering:
    • Active user override
    • Override across all hosts
    • Token resolution with insecure and secure (keyring) storage
    • Unknown user returns no token

Note: The flag is named --account rather than --user to avoid conflicts with the existing --user/-u flags on several subcommands (auth switch, auth token, auth logout, secret, codespace, run list).

Fixes #13088

Add a global --account persistent flag that overrides the active GitHub
account for a single command invocation, eliminating the error-prone
pattern of switching accounts globally with gh auth switch.

Changes:
- Add SetActiveUser method to AuthConfig interface and implementation
- Modify ActiveUser to check activeUserOverride before config lookup
- Modify ActiveToken to use overridden user's token via TokenForUser
- Add --account persistent flag to root command
- Wire flag in PersistentPreRunE before auth check

Fixes cli#13088

Co-authored-by: Copilot <[email protected]>
@cataggar
cataggar requested a review from a team as a code owner April 3, 2026 09:37
@cataggar
cataggar requested review from babakks and Copilot April 3, 2026 09:37
@github-actions github-actions Bot added external pull request originating outside of the CLI core team needs-triage needs to be reviewed unmet-requirements and removed needs-triage needs to be reviewed labels Apr 3, 2026
@github-actions

github-actions Bot commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

Thanks for your pull request! Unfortunately, it doesn't meet the minimum requirements for review:

  • None of the referenced issues have the help wanted label

Please update your PR to address the above. Requirements:

  1. Include a detailed description of what this PR does
  2. Link to an issue with the help wanted label (use Fixes #123 or Closes #123 if it resolves the issue)

This PR will be automatically closed in 7 days if these requirements are not met.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a global --account flag to allow selecting a specific authenticated GitHub user for a single gh command invocation, avoiding the need to gh auth switch back and forth.

Changes:

  • Added SetActiveUser(user string) to the gh.AuthConfig interface and implemented it in internal/config.AuthConfig.
  • Updated auth resolution to prefer an in-memory active-user override for ActiveUser() and ActiveToken().
  • Added a root persistent --account flag and applied it during PersistentPreRunE before auth checks; added unit tests for override behavior and token lookup.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 2 comments.

File Description
pkg/cmd/root/root.go Introduces --account persistent flag and applies the override during root pre-run.
internal/gh/gh.go Extends the AuthConfig interface with SetActiveUser.
internal/config/config.go Stores an active-user override and uses it for ActiveUser/ActiveToken resolution.
internal/config/auth_config_test.go Adds unit tests covering active-user override and token resolution paths.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread pkg/cmd/root/root.go
Comment on lines +79 to +82
// apply per-invocation user override if --account flag is set
if account, err := cmd.Flags().GetString("account"); err == nil && account != "" {
cfg.Authentication().SetActiveUser(account)
}

Copilot AI Apr 3, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

--account currently gets applied without any validation, and errors from GetString("account") are silently ignored. Because cmdutil.CheckAuth only checks HasEnvToken() or len(Hosts()) > 0, a typo/unknown account will still pass the auth gate and commands will proceed with an empty token, leading to later authorization failures that are harder to diagnose. Consider: (1) returning the flag lookup error, and (2) when --account is set, verifying that the specified user has a token on at least one known host (or at minimum on the default host) and returning a clear error if not.

Copilot uses AI. Check for mistakes.
Comment thread internal/gh/gh.go
Comment on lines 154 to +173
// The following methods are only for testing and that is a design smell we should consider fixing.

// SetActiveToken will override any token resolution and return the given token and source for all calls to
// ActiveToken.
// Use for testing purposes only.
SetActiveToken(token, source string)

// SetHosts will override any hosts resolution and return the given hosts for all calls to Hosts.
// Use for testing purposes only.
SetHosts(hosts []string)

// SetDefaultHost will override any host resolution and return the given host and source for all calls to
// DefaultHost.
// Use for testing purposes only.
SetDefaultHost(host, source string)

// SetActiveUser will override the active user resolution for all hosts, returning the given user
// for all calls to ActiveUser and using that user's token for all calls to ActiveToken.
// This is used by the --user flag to override the active account per-invocation.
SetActiveUser(user string)

Copilot AI Apr 3, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The doc comment for SetActiveUser says it is used by a --user flag, but this PR introduces --account. Also, SetActiveUser is placed after the “only for testing” section header even though it is used in production code. Please update the comment to reference --account and either move SetActiveUser above the test-only section or adjust the section comment so it’s not misleading.

Copilot uses AI. Check for mistakes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

external pull request originating outside of the CLI core team unmet-requirements

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Feature: per-command user selection (--user flag)

2 participants