AnswerDotAI / AnswerDotAI/ghapi

Starting example results in 404, should specify JWT to make it work

Open
#147 0 comments 2 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
685
Forks
70
Avg merge
1m
Merged PRs (30d)
2

Description

The simple example results in a 404 error:
```python
api = GhApi(owner='owner', repo='repo', token='')
pulls = api.pulls.list()
```

but with curl it works (from GitHub docs):
```sh
curl \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer " \
https://api.github.com/repos/OWNER/REPO/pulls
```

The following works:
```python
api = GhApi(owner='owner', repo='repo', jwt_token='')
pulls = api.pulls.list()
```

The personal access token has scopes for repo, workflow, gist and notifications.

# Cause

It seems the API call to GitHub expects a different header. The example on GhApi sets `Authorization: token ` but the example on GitHub specifies `Authorization: Bearer `. On https://docs.github.com/en/rest/overview/other-authentication-methods this is expanded upon with the note:
> Note: In most cases, you can use Authorization: Bearer or Authorization: token to pass a token. However, if you are passing a JSON web token (JWT), you must use Authorization: Bearer.

Reading the docs I assume the header `Authorization: token ` is fine, but the above experimentation indicates otherwise.

# Conclusion
I have no clue why 'my' token is regarded as a JWT token here, and in the example of GhApi not. For me it works, but I couldn't find a reason. Perhaps it helps someone searching for this, but I'm also interested to known if it is a setting or ...

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.