Repository navigation
Conversation
The CAPI transport sets the Authorization header itself, which bypasses the base HTTP client's auto-refresh. Pass the AuthConfig through to the transport so it resolves the token through ActiveTokenWithRefresh on each request, renewing a near-expiry short-lived token just before use. Co-authored-by: Copilot <[email protected]> Copilot-Session: 2dc3f23c-61a6-43a7-85cd-90aa872a7fc6
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The new per-request refresh behavior lacks focused unit coverage proving token lookup and header replacement.
Review effort: Balanced
Findings: 1
What changed in this PR
Updates agent-task CAPI requests to resolve and refresh credentials immediately before each request.
Changes:
- Injects authentication configuration into the CAPI client.
- Resolves the active token per request.
- Adapts existing tests to the new constructor signature.
| File | Description |
|---|---|
pkg/cmd/agent-task/shared/capi.go |
Passes authentication configuration to CAPI. |
pkg/cmd/agent-task/capi/client.go |
Adds per-request token refresh. |
pkg/cmd/agent-task/capi/job_test.go |
Adds the authentication test stub. |
pkg/cmd/agent-task/capi/sessions_test.go |
Updates client construction in session tests. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| cred, _, _ := ct.authCfg.ActiveTokenWithRefresh(ct.host) | ||
| req.Header.Set("Authorization", "Bearer "+cred.Token) |
williammartin
left a comment
There was a problem hiding this comment.
I can't leave a review comment on here but this doesn't fix insecure-storage because that creates a new entry in hosts.yml and
cli/pkg/cmd/agent-task/agent_task.go
Lines 91 to 99 in 17142e0
Doesn't check this. Also, this whole idea that only oauth tokens are stored in hosts.yml is just broken i.e. --with-token.

Part of #14449. Based on #14454 (auth status).
Description
The last consumer seam: refresh a short-lived token per agent-task/CAPI request, so agent-task calls made through the CAPI client also travel with a currently valid credential instead of an expired one.
How did you test this change?
This feature is verified end to end as a whole rather than per PR. End-to-end tests should pass.
Key points
gh auth token,gh auth status, and the git credential helper already refresh before use; the agent-task/CAPI client is the remaining token consumer, and this PR gives it the same treatment.Notes for reviewers
Small PR; focus on where the CAPI client obtains the token and how the refresh is invoked before the request. The behavior mirrors the other consumer seams, so it should read as the same pattern applied once more.
Commit:
fix(agent-task/capi): refresh short-lived tokens per CAPI requestAuthorship and follow-up
Who wrote this:
Who answers review comments: