github / github/copilot-sdk

[Task] Add automatic GitHub App token refresh to the Copilot SDK

Aperta
#2,540 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
enhancement
Lingua principale
Java
Stelle
10.5k
Fork
1.5k
Merge medio
1g 11h
PR unite (30g)
127

Descrizione

## Outcome

Long-running SDK sessions can refresh GitHub App credentials without restarting the session or forcing repeated OAuth flows.

## Scope

- Add a supported credential-provider mechanism for lazy or proactive refresh
- Support S2S installation token re-minting before or after the one-hour expiry
- Support U2S refresh tokens and discoverable token lifetime policies
- Retry safely when a token expires during a turn
- Replace reliance on the experimental `session.auth.setCredentials` workaround
- Preserve existing static token behavior

## Acceptance criteria

- [ ] A session running longer than one S2S token lifetime continues without manual token injection
- [ ] A request encountering token expiry can obtain a fresh credential and retry without duplicating unsafe work
- [ ] U2S refresh does not force a new interactive OAuth flow on normal expiry
- [ ] Refresh failures surface clearly and never silently fall back to another identity
- [ ] Node, Go, .NET, and Java SDK behavior is consistent or explicitly staged
- [ ] Public SDK documentation includes secure private-key and refresh guidance

## Dependencies

Coordinate runtime credential update behavior with the bundled CLI. The basic `gitHubToken` acceptance fix remains tracked in github/copilot#30423.

## References

- Parent epic https://github.com/github/copilot/issues/30409
- ADR https://github.com/github/copilot/pull/30449
- Existing prior art github/copilot-sdk#1748

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Start with ADR github/copilot#30449, prior art github/copilot-sdk#1748, and the parent epic github/copilot#30409. Review the SDK credential-provider and session-auth entry points, then coordinate runtime credential updates with the bundled CLI. Done means safe S2S and U2S refresh, expiry retry behavior, preserved static tokens, consistent or staged SDK behavior, and secure public documentation.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
github, go, java, node.js
Ambito
api, authentication, backend-api-design, security
Tipo di issue
Funzionalità
Difficoltà
5/5
Tempo stimato
Più di una settimana
Stato di attività
Attiva
Chiarezza
Abbastanza chiara
Idoneità per principianti
30/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.