github / github/app

Support a configurable local WebSocket port for enterprise firewall environments

未关闭
#2,007 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
没有语言数据
星标
2.1k
派生
153
PR 合并指标
30 天内没有已合并 PR

描述

### Feature summary

_No response_

### What problem are you trying to solve?

The GitHub Copilot app uses dynamically allocated localhost ports for communication between the app UI/WebView and its backend.

On Windows, these ports appear to be selected from the dynamic TCP port range (49152–65535). In our enterprise environment, endpoint web filtering and security software restrict traffic within this range, including localhost WebSocket connections.

As a result, the app repeatedly fails to establish or maintain its local WebSocket connection and authentication cannot complete. The logs show errors such as:

* `Connection reset without closing handshake`
* `IO error: An established connection was aborted by the software in your host machine (os error 10053)`

We confirmed the following:

* Access to the GitHub Enterprise host over TCP 443 works.
* The bundled `gh.exe` can authenticate successfully and access the GitHub Enterprise API.
* The Copilot app works when the Windows dynamic port range 49152–65535 is temporarily allowed.
* The app also works when the endpoint filtering software is temporarily disabled.
* The WebSocket listener port changes each time the app starts.

Allowing the entire Windows dynamic port range is difficult to approve as a permanent enterprise security configuration. We therefore need a supported way to configure or restrict the localhost ports used by the GitHub Copilot app.

### Proposed solution

Please provide a supported configuration option, environment variable, or command-line argument to control the localhost listener ports used by the GitHub Copilot app.

Ideally, administrators should be able to configure:

* A fixed WebSocket listener port
* A fixed Git trampoline or broker port
* Alternatively, a limited configurable port range

For example:

```text
--websocket-port 55000
--trampoline-port 55001
```

or:

```text
COPILOT_APP_WEBSOCKET_PORT=55000
COPILOT_APP_TRAMPOLINE_PORT=55001
```

This would allow enterprise administrators to create narrow, application-specific security exceptions instead of permitting the entire Windows dynamic port range.

### Workflow impact

_No response_

### Installation context

_No response_

### Additional context

_No response_

贡献指南

打开贡献指南

调研方向

The issue names no source files, tests, or entry points. Start by locating the app's localhost WebSocket listener and Git trampoline or broker setup, then determine how configuration is loaded. Done means administrators can configure the requested local ports or a constrained range and the connection and authentication flow works in the stated enterprise environment.

由索引模型根据 Issue 内容生成。

评估

技术栈
github
领域
authentication, desktop, networking
Issue 类型
功能
难度
5/5
预计耗时
一周以上
活跃度
冷清
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。