Keep the stored GitHub token when setup runs again

The secret store outlives the sandbox, so recreating one to change its image
or add a profile does not lose the token. Prompting for a replacement anyway
made --replace impractical and trained the habit of minting tokens that are
never revoked.

Only a token scoped to this sandbox counts. A global one would authenticate
the agent too, but reaching every repository it can reach is what this task
exists to prevent. The token command still always prompts; it is the way to
replace an expired or revoked token.
This commit is contained in:
2026-08-03 16:09:44 -05:00
parent 53db7df812
commit b5dfae0696
3 changed files with 116 additions and 5 deletions
+24 -3
View File
@@ -83,8 +83,10 @@ Usage:
mise run ai:sbx -- status
mise run ai:sbx -- remove
Setup opens a pre-filled GitHub token form in your browser. Use "token" on
its own to replace an expired or revoked token later.
Setup opens a pre-filled GitHub token form in your browser, unless a token is
already stored for the sandbox. The secret store outlives the sandbox, so
recreating one with --replace keeps its token. Use "token" on its own to
replace an expired or revoked token.
Set AI_SBX_TEMPLATE in your mise config to reuse one custom image across
every repository without repeating --template.
@@ -242,6 +244,17 @@ read_token() {
printf '%s' "$token"
}
# Only a token scoped to this sandbox counts. A global one would authenticate
# the agent too, but reaching every repository the token can reach is exactly
# what this task exists to prevent, so it is not treated as satisfying setup.
sandbox_has_github_token() {
sbx secret ls 2>/dev/null |
awk -v scope="$SANDBOX_NAME" '
$1 == scope && $2 == "service" && $3 == "github" { found = 1 }
END { exit !found }
'
}
install_github_token() {
local url
url="$(token_url)"
@@ -1354,7 +1367,15 @@ setup_command() {
create_sandbox
fi
install_github_token
# The secret store outlives the sandbox, so recreating one to change its
# image keeps the token. Prompting anyway would train the habit of minting
# replacement tokens and never revoking the old ones.
if sandbox_has_github_token; then
printf 'Keeping the GitHub token already stored for %s. Replace it with: mise run ai:sbx -- token\n' \
"$SANDBOX_NAME"
else
install_github_token
fi
install_sandbox_aws_files