github / github/copilot-cli

/delegate fails with 403 during UncommittedChangesCheck pre-flight ("Request forbidden by administrative rules") despite valid auth and repo access

Chiusa
#4,657 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

area:authentication area:networking
Lingua principale
Shell
Stelle
11.2k
Fork
1.9k
Merge medio
14h 16m
PR unite (30g)
6

Descrizione

Description

Running /delegate in Copilot CLI on a valid, authenticated repo consistently fails during the pre-flight UncommittedChangesCheck stage with a 403 error, even though the same GitHub API endpoint succeeds when called directly via curl/gh api with the same credentials.

Environment

  • Copilot CLI version: 1.0.81
  • OS: macOS
  • Repo: GroupiSP/probreg (public repo, non-fork)
  • Auth: gh OAuth token, scopes admin:public_key, gist, read:org, repo
  • Confirmed repo permissions for user: admin: true, maintain: true, pull: true, push: true, triage: true

Steps to reproduce

  1. In an authenticated Copilot CLI session on GroupiSP/probreg (branch main), run /delegate.
  2. Observe failure during pre-flight validation.

Error from CLI logs (~/.copilot/logs/process-*.log)

2026-08-28T20:54:54.846Z [INFO] STAGE 1: UncommittedChangesCheck - Starting validation checks
2026-08-28T20:54:54.976Z [INFO] Repository: GroupiSP/probreg (host: github.com)
2026-08-28T20:54:54.976Z [INFO] Base branch: main, Head branch: main
2026-08-28T20:54:54.976Z [INFO] Async branch: copilot/established-meadowlark
2026-08-28T20:54:55.308Z [INFO] Running parallel validation checks...
2026-08-28T20:54:55.373Z [ERROR] Request to GitHub Repository API at https://api.github.com/repos/GroupiSP/probreg failed with status 403 (request ID: unknown), body:
Request forbidden by administrative rules. Please make sure your request has a User-Agent header (https://docs.github.com/en/rest/overview/resources-in-the-rest-api#user-agent-required). Check https://developer.github.com for other possible causes.

2026-08-28T20:54:55.373Z [ERROR] Failed during uncommitted changes check: Error: HTTP 403 response does not appear to originate from GitHub. Is a proxy or firewall intercepting this request? https://gh.io/copilot-firewall

Investigation performed

  • No proxy/VPN or HTTP(S)_PROXY env vars set; TLS certs for api.github.com / api.githubcopilot.com verify correctly with valid GitHub-issued certs (not proxy re-signed).
  • The exact same endpoint (GET https://api.github.com/repos/GroupiSP/probreg) returns 200 OK reliably (5+ consecutive attempts) via curl and gh api using the same token, both with and without an explicit User-Agent header.
  • gh auth status shows a valid, active token; org (GroupiSP) membership and repo push/admin access confirmed via API.
  • Rate limit unaffected: 5000/5000 remaining at time of failure.
  • The response body explicitly complains about a missing User-Agent header, and lacks the usual x-github-request-id header — suggesting the CLI's internal HTTP client for this specific pre-flight request may be omitting/malforming the User-Agent header, or hitting a GitHub edge/WAF rule specific to this request path/session, rather than a client-side network intercept.

Expected behavior

/delegate's pre-flight check should succeed using the same authenticated context that other CLI operations (e.g., tool calls to gh api) use successfully.

Suggested area to check

The HTTP client used specifically for STAGE 1: UncommittedChangesCheck — likely missing/invalid User-Agent header on outgoing request, or the request identity differs from the normally-authenticated gh-based path.

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Direzione di ricerca

Riproduci /delegate su GroupiSP/probreg e ispeziona ~/.copilot/logs/process-*.log alla voce STAGE 1: UncommittedChangesCheck. Confronta la richiesta del repository che fallisce con la richiesta curl o gh api riuscita, concentrandoti sugli header della richiesta e sull’identità utilizzata dal client HTTP interno. Il lavoro è completato quando il controllo preliminare ha esito positivo con il contesto autenticato esistente e non si verifica alcun 403.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
github, shell
Ambito
api, cli, networking
Tipo di issue
Bug
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Attiva
Chiarezza
Abbastanza chiara
Idoneità per principianti
55/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.