Local sandbox 'Authenticate gh' silently uses an unrelated cached fine-grained PAT instead of active gh OAuth session, with no visibility into which credential is chosen
Personne n'a encore pris cette issue.
- Langage dominant
- Shell
- Étoiles
- 11.2k
- Forks
- 1.9k
- Merge moyen
- 14 h 16 min
- PR mergées (30 j)
- 6
Description
Describe the bug
With local sandboxing enabled (/sandbox enable) and the "Authenticate gh" auth setting on (default), the GH_TOKEN exported into the sandboxed environment did not correspond to my active gh session.
gh auth status(run on the host, outside the sandbox) showed I was logged in via the OAuth device flow, with agho_...token and scopesadmin:public_key,gist,read:org,repo— i.e. full private repo access.- Inside a Copilot CLI sandboxed session,
echo $GH_TOKEN/gh repo list <org> --visibility privateshowed access to only one private repository in my org, via a token in the fine-grained PAT format (github_pat_...). - After investigating, I found the actual token being used: an old fine-grained PAT I had created previously and scoped intentionally to a single, unrelated repository (not the repo I was actively working in).
- This PAT is neither the active
gh auth statusOAuth session (keyring-storedgho_token) nor the GitHub Appghu_token found in~/.config/github-copilot/auth.db.
I was unable to determine, from inside a Copilot CLI session or from documentation, why this specific cached PAT was selected over my active OAuth login, or where exactly it was being read from/cached. The lack of visibility made this very difficult to diagnose — I only found the answer by manually checking GitHub's "Active tokens" org admin page and recognizing a token I had created weeks earlier for unrelated purposes.
Expected behavior
When "Authenticate gh" is enabled for the local sandbox, I would expect one of the following:
- The sandbox's
GH_TOKENto be derived from the currently activegh auth statusaccount/session (respectinggh auth switch), not from some other cached credential, OR - If Copilot CLI intentionally uses a different/cached credential for the sandbox (e.g. a previously-supplied
GH_TOKEN/GITHUB_TOKENenv var), this should be clearly surfaced to the user — e.g. via/sandboxor/env, showing which token/account is being exported into the sandbox and why, without requiring the user to manually diff PAT prefixes and check GitHub's org "Active tokens" page.
Reproduction steps
- Log in normally via
gh auth login(OAuth device flow), confirm withgh auth statusthat the active session has broadreposcope. - Separately, at some earlier point, create (or have previously created) a fine-grained PAT scoped to only one specific repository, for an unrelated purpose.
- Launch
copilot, enable local sandboxing (/experimental onif needed, then/sandbox enable), leave "Authenticate gh" at its default (on). - Inside the Copilot CLI session, ask the agent to run
gh repo list <org> --visibility privateor inspect$GH_TOKEN. - Observe that the token exported into the sandbox matches the old, narrowly-scoped fine-grained PAT from step 2 — not the active OAuth session from step 1 — with no indication in the CLI of which credential was selected or why.
Additional context
/envand/sandboxdo not currently surface which specific token/account was selected forGH_TOKENin the sandbox, making this essentially undiagnosable without manual, external investigation (comparing token prefixes, checking org "Active tokens" pages, etc.).- Docs reference (
Configuring local sandbox settings→ Auth tab): "Authenticate gh: Export GH_TOKEN so that GitHub CLI ... works inside the sandbox without reaching its stored credentials (configuration directory or OS keychain), which the sandbox blocks." This explains that a substitute token is exported, but not how that substitute is selected when multiple credentials (OAuth session, GitHub App ghu_ token, cached fine-grained PATs) exist on the host. - Related open issues that touch on adjacent auth-scoping concerns: #1460 (no scoped-auth workflow vs
gh auth login), #953 (default OAuth grants excessive scope).
Suggested improvement
- Add a way to inspect, from within a session (e.g.
/sandboxAuth tab or/env), exactly which token/account is currently selected for sandboxedgh/git operations, including its origin (activegh auth statussession vs. a manually-setGH_TOKEN/GITHUB_TOKENenv var vs. some other cached credential) and its repository scope. - Consider making the sandboxed
GH_TOKENfollow the currently activegh auth statusaccount by default, rather than silently preferring a possibly-staleGH_TOKEN/GITHUB_TOKENenv var or other cached credential.
Guide de contribution
Ouvrir le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Piste de recherche
Aucun fichier d’implémentation ni aucun test n’est nommé. Commencez par retracer le parcours d’authentification du sandbox local derrière /sandbox enable, les vues Auth de /env et du sandbox, ainsi que le paramètre documenté Authenticate gh ; comparez la sélection des identifiants avec gh auth status et ~/.config/github-copilot/auth.db. C’est terminé lorsque l’origine et la portée de l’identifiant sélectionné sont visibles et que le comportement de sélection signalé est couvert par un test de régression.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- github, shell
- Domaine
- authentication, cli, security
- Type d'issue
- Bug
- Difficulté
- 4/5
- Temps estimé
- 3-5 jours
- Activité
- Active
- Clarté
- Plutôt claire
- Accessibilité débutants
- 52/100