Keep the stored GitHub token when setup runs again
The secret store outlives the sandbox, so recreating one to change its image or add a profile does not lose the token. Prompting for a replacement anyway made --replace impractical and trained the habit of minting tokens that are never revoked. Only a token scoped to this sandbox counts. A global one would authenticate the agent too, but reaching every repository it can reach is what this task exists to prevent. The token command still always prompts; it is the way to replace an expired or revoked token.
This commit is contained in:
+24
-3
@@ -83,8 +83,10 @@ Usage:
|
||||
mise run ai:sbx -- status
|
||||
mise run ai:sbx -- remove
|
||||
|
||||
Setup opens a pre-filled GitHub token form in your browser. Use "token" on
|
||||
its own to replace an expired or revoked token later.
|
||||
Setup opens a pre-filled GitHub token form in your browser, unless a token is
|
||||
already stored for the sandbox. The secret store outlives the sandbox, so
|
||||
recreating one with --replace keeps its token. Use "token" on its own to
|
||||
replace an expired or revoked token.
|
||||
|
||||
Set AI_SBX_TEMPLATE in your mise config to reuse one custom image across
|
||||
every repository without repeating --template.
|
||||
@@ -242,6 +244,17 @@ read_token() {
|
||||
printf '%s' "$token"
|
||||
}
|
||||
|
||||
# Only a token scoped to this sandbox counts. A global one would authenticate
|
||||
# the agent too, but reaching every repository the token can reach is exactly
|
||||
# what this task exists to prevent, so it is not treated as satisfying setup.
|
||||
sandbox_has_github_token() {
|
||||
sbx secret ls 2>/dev/null |
|
||||
awk -v scope="$SANDBOX_NAME" '
|
||||
$1 == scope && $2 == "service" && $3 == "github" { found = 1 }
|
||||
END { exit !found }
|
||||
'
|
||||
}
|
||||
|
||||
install_github_token() {
|
||||
local url
|
||||
url="$(token_url)"
|
||||
@@ -1354,7 +1367,15 @@ setup_command() {
|
||||
create_sandbox
|
||||
fi
|
||||
|
||||
install_github_token
|
||||
# The secret store outlives the sandbox, so recreating one to change its
|
||||
# image keeps the token. Prompting anyway would train the habit of minting
|
||||
# replacement tokens and never revoking the old ones.
|
||||
if sandbox_has_github_token; then
|
||||
printf 'Keeping the GitHub token already stored for %s. Replace it with: mise run ai:sbx -- token\n' \
|
||||
"$SANDBOX_NAME"
|
||||
else
|
||||
install_github_token
|
||||
fi
|
||||
|
||||
install_sandbox_aws_files
|
||||
|
||||
|
||||
Reference in New Issue
Block a user