Skip to content

feat(setup-repo): offer to add GH_TOKEN to the env-file for GitHub repos - #308

Merged
tildesrc merged 4 commits into
mainfrom
panopticon/setup-repo-github-token
Jul 13, 2026
Merged

tildesrc merged 4 commits into
mainfrom
panopticon/setup-repo-github-token

Conversation

@tildesrc

Copy link
Copy Markdown
Contributor

Adds a step to the setup-repo shell workflow that offers to record a GitHub token in the repo's env-file — but only when it's both wanted and missing.

What it does

After the existing claude setup-token credential handling, the script offers to add GH_TOKEN to the repo's env-file, gated on all three:

  1. The repo is hosted on GitHub — its git_url names github.com (handles both HTTPS https://github.com/owner/repo.git and SSH git@github.com:owner/repo.git remote forms).
  2. A GH_TOKEN is present in the environment — e.g. the operator's own shell (the shell runner inherits the host env).
  3. The env-file has no active GH_TOKEN line yet — never clobbers an existing token.

On accept it appends GH_TOKEN=<value> to the env-file (private 0600 perms), so future task containers can use gh and push over HTTPS. The outcome folds into the existing summary; the complete-on-Enter finish is unchanged. When any gate fails the step is a silent no-op — no behavior change for existing setups.

How

  • Plumb git_url into the shell session — ShellRunner.spawn gains a git_url param exported as PANOPTICON_GIT_URL; spawner._spawn_shell passes repo["git_url"] so the script can detect the forge.
  • Three new sourceable helpers in setup_repo_lib.sh: is_github_url, env_file_has_var, and append_env_var (append with a trailing-newline guard, private perms).
  • New maybe_offer_github_token step in setup_repo.sh, run after the credential branch and before the summary.

No Repo model change — GitHub-ness is derived from the existing git_url at runtime. GitHub Enterprise hosts and token rotation are out of scope.

🤖 Generated with Claude Code

Panopticon Agent and others added 4 commits July 13, 2026 04:47
Add a step to the setup-repo workflow that offers to record a GitHub token
in the repo's env-file, gated on all three of: the repo is hosted on GitHub
(its git_url names github.com), a GH_TOKEN is present in the environment
(e.g. the operator's own shell — the shell runner inherits the host env),
and the env-file has no active GH_TOKEN line yet. On accept it appends
GH_TOKEN to the env-file (private perms); the outcome folds into the
existing summary and the complete-on-Enter finish is unchanged.

Plumb the repo's git_url into the shell session as PANOPTICON_GIT_URL
(ShellRunner.spawn gains a git_url param; the spawner passes repo["git_url"])
so the script can detect the forge. Add sourceable helpers is_github_url,
env_file_has_var, and append_env_var.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Move the GitHub-token offer ahead of the Claude credential flow — it's a
quick host-side copy that shouldn't wait behind the (possibly interactive)
`claude setup-token`. Introduce an `add_summary` helper so each step appends
its own clause to the summary; the order the steps run in no longer clobbers
it (the Claude branches previously overwrote the summary wholesale).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Move the GitHub-token offer back to after the Claude credential flow. The
add_summary helper stays, so each step still appends its own clause and the
summary combines both outcomes regardless of order.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@tildesrc
tildesrc marked this pull request as ready for review July 13, 2026 14:49
@tildesrc
tildesrc merged commit 88e99a4 into main Jul 13, 2026
3 checks passed
tildesrc pushed a commit that referenced this pull request Jul 13, 2026
… storage

Build on #308's GH_TOKEN support with the operator-UX improvements:

* Open with two bulleted lists — what we know about the repo (name +
  local-checkout vs GitHub-remote, classified from the git URL) and what its
  setup entails (Claude credential always; GH_TOKEN for GitHub repos), each
  marked needed / already-configured / not-needed.
* GH_TOKEN acquisition now combines both paths: reuse a GH_TOKEN already in the
  environment (#308's fast path) when present, else authenticate interactively
  via `gh auth login` + `gh auth token`. Offers to replace an existing
  GH_TOKEN, and guides the operator when `gh` isn't installed.
* DRY the env-file write: generalize `store_oauth_token` into
  `store_env_token <VAR> <token> <file>`, the single comment-out/replace/append
  implementation both tokens share (retires the append-only `append_env_var`);
  `store_oauth_token` stays as a thin wrapper.
* Turn the closing summary into a bullet-per-step list.
* Fold in #309's hint wording (detach reassurance + actionable drop).

The opening summary needs the repo's name, so the ShellRunner now also exports
PANOPTICON_REPO_NAME (alongside #308's PANOPTICON_GIT_URL), passed through by
the spawner from the repo record.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
tildesrc added a commit that referenced this pull request Jul 14, 2026
…orage (#310)

* feat(setup-repo): repo-aware summaries + gh-login GH_TOKEN, DRY token storage

Build on #308's GH_TOKEN support with the operator-UX improvements:

* Open with two bulleted lists — what we know about the repo (name +
  local-checkout vs GitHub-remote, classified from the git URL) and what its
  setup entails (Claude credential always; GH_TOKEN for GitHub repos), each
  marked needed / already-configured / not-needed.
* GH_TOKEN acquisition now combines both paths: reuse a GH_TOKEN already in the
  environment (#308's fast path) when present, else authenticate interactively
  via `gh auth login` + `gh auth token`. Offers to replace an existing
  GH_TOKEN, and guides the operator when `gh` isn't installed.
* DRY the env-file write: generalize `store_oauth_token` into
  `store_env_token <VAR> <token> <file>`, the single comment-out/replace/append
  implementation both tokens share (retires the append-only `append_env_var`);
  `store_oauth_token` stays as a thin wrapper.
* Turn the closing summary into a bullet-per-step list.
* Fold in #309's hint wording (detach reassurance + actionable drop).

The opening summary needs the repo's name, so the ShellRunner now also exports
PANOPTICON_REPO_NAME (alongside #308's PANOPTICON_GIT_URL), passed through by
the spawner from the repo record.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(shell-runner): strip comments so the spawn command fits tmux's imsg cap

The setup-repo UX changes grew the assembled shell command to ~18 KB. tmux
sends a whole `new-session` command (pane shell command included) to its server
over imsg, which caps a single message at MAX_IMSGSIZE (16 KiB) — so the spawn
failed with `new-session ... returned non-zero exit status 1` before the script
ever ran.

Strip whole-line comments and blank lines from the assembled command at spawn
time (they're pure bulk at runtime; the source files keep their comments). This
brings setup-repo's command from ~18 KB to ~10 KB, well under the cap, and gives
every shell workflow headroom. Only lines that are entirely a comment or blank
are dropped — inline/trailing comments and code are untouched.

Adds a tmux-free regression test asserting the assembled setup-repo command has
no whole-line comments and stays under 16 KiB (the pytest CI job has no tmux, so
the integration spawn test is skipped there — this guards it without one).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* feat(setup-repo): drop the gh auth login fallback for GH_TOKEN

Keep only the reuse-a-GH_TOKEN-from-the-environment path: when the operator's
env has a GH_TOKEN, offer to write it into the env-file (through the shared
store_env_token, so an existing one is replaced); when it doesn't, guide them to
add one by hand rather than minting one interactively. Removes collect_gh_token
and the `gh auth login`/`gh auth token` flow.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* feat(setup-repo): open with the credentials goal + why

Begin the flow with a short intro stating the goal — collect persistent
credentials (a Claude token, and a GH_TOKEN for GitHub repos) stored in the
repo's env-file so Claude can use them inside task containers — and the reason:
the agent runs on its own dedicated credentials instead of hijacking the
operator's.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* feat(setup-repo): trustworthy credential flow — adopt/paste/mint, env-file truth

Address the self-review of the onboarding flow:

Correctness
* "Configured" is now checked against the env-file (env_file_has_var), not the
  sourced env. A Claude token that lives only in the operator's shell is no
  longer mis-reported as configured (the container gets --env-file, not the host
  env), which previously meant "done" but a container that 401s.

Consent / control
* Every adopt prompt defaults to No ([y/N]); flipped GH adoption off [Y/n].
* Adopting a token from the environment shows a masked tail (last 4) so the
  operator confirms which token — new mask_last4 helper.
* Only offers to adopt a var that isn't already the env-file's own.

Fast path for an already-authenticated operator
* Each credential can be adopted from the environment or pasted inline; Claude
  falls back to `claude setup-token`. Symmetric Claude/GH via a shared
  store_token. No more detach → drop → hand-edit → re-run to bring your own.

Copy
* New opener: what happens + that you stay in control (per-repo tokens, "not
  your personal session", opt out by editing the env-file) — drops the
  "collect persistent credentials"/"hijacking" register.
* "collect" → "mint / set up" throughout; agent-neutral wording.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Panopticon Agent <agent@panopticon.local>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant