Session creation shows generic "Failed to initialize workspace" when SAML SSO token expires
- Dominant language
- No language data
- Stars
- 2.1k
- Forks
- 153
- PR merge metrics
- No merged PRs in 30d
Description
## Describe the bug
When an organization enforces SAML SSO and the OAuth token authorization lapses, creating a new session fails with `Session creation failed: Failed to initialize workspace`. The actual cause — a 403 with "you must re-authorize the OAuth Application" — is only visible in `~/.copilot/logs/`.
## Expected behavior
1. The UI should surface the SAML SSO error directly, ideally with a clickable re-authorization link
2. After re-authorizing on GitHub.com, the app should automatically detect the refreshed authorization and retry — not require a full app restart
## Steps to reproduce
1. Be a member of an org with enforced SAML SSO
2. Wait for SSO authorization to expire
3. Try to create a new session in a repo owned by that org
4. See generic "Failed to initialize workspace"
## Logs
```
fatal: unable to access '...': The requested URL returned error: 403
remote: The 'org' organization has enabled or enforced SAML SSO.
remote: To access this repository, you must re-authorize the OAuth Application 'GitHub'.
```
## Environment
- Windows, Copilot app v1.0.80
Contributor guide
Research direction
Reproduce session creation on Windows with an organization enforcing SAML SSO, then inspect ~/.copilot/logs/ while tracing the desktop UI's new-session flow. Verify that the 403 and re-authorization link are surfaced, and that the refreshed authorization is detected so session creation retries without restarting the app.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github
- Domain
- authentication, authorization, desktop
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 52/100