Support a configurable local WebSocket port for enterprise firewall environments
- 主要言語
- 言語のデータがありません
- スター
- 2.1k
- フォーク
- 153
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
### Feature summary
_No response_
### What problem are you trying to solve?
The GitHub Copilot app uses dynamically allocated localhost ports for communication between the app UI/WebView and its backend.
On Windows, these ports appear to be selected from the dynamic TCP port range (49152–65535). In our enterprise environment, endpoint web filtering and security software restrict traffic within this range, including localhost WebSocket connections.
As a result, the app repeatedly fails to establish or maintain its local WebSocket connection and authentication cannot complete. The logs show errors such as:
* `Connection reset without closing handshake`
* `IO error: An established connection was aborted by the software in your host machine (os error 10053)`
We confirmed the following:
* Access to the GitHub Enterprise host over TCP 443 works.
* The bundled `gh.exe` can authenticate successfully and access the GitHub Enterprise API.
* The Copilot app works when the Windows dynamic port range 49152–65535 is temporarily allowed.
* The app also works when the endpoint filtering software is temporarily disabled.
* The WebSocket listener port changes each time the app starts.
Allowing the entire Windows dynamic port range is difficult to approve as a permanent enterprise security configuration. We therefore need a supported way to configure or restrict the localhost ports used by the GitHub Copilot app.
### Proposed solution
Please provide a supported configuration option, environment variable, or command-line argument to control the localhost listener ports used by the GitHub Copilot app.
Ideally, administrators should be able to configure:
* A fixed WebSocket listener port
* A fixed Git trampoline or broker port
* Alternatively, a limited configurable port range
For example:
```text
--websocket-port 55000
--trampoline-port 55001
```
or:
```text
COPILOT_APP_WEBSOCKET_PORT=55000
COPILOT_APP_TRAMPOLINE_PORT=55001
```
This would allow enterprise administrators to create narrow, application-specific security exceptions instead of permitting the entire Windows dynamic port range.
### Workflow impact
_No response_
### Installation context
_No response_
### Additional context
_No response_
コントリビューションガイド
調査の方向性
この issue では、ソースファイル、テスト、エントリポイントが指定されていません。まず、アプリの localhost WebSocket リスナーと Git trampoline または broker のセットアップを特定し、次に設定がどのように読み込まれるかを確認してください。管理者が要求されたローカルポートまたは制限された範囲を設定でき、指定されたエンタープライズ環境で接続および認証フローが機能すれば完了です。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- github
- 領域
- authentication, desktop, networking
- issue の種類
- 機能追加
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 活発さ
- 静か
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 35/100