Skip to content

feat(github): show granted OAuth scopes and warn when repo is missing - #356

Open
Goodyslim wants to merge 1 commit into
AyinkxLab:mainfrom
Goodyslim:feat/57-granted-oauth-scopes
Open

Goodyslim wants to merge 1 commit into
AyinkxLab:mainfrom
Goodyslim:feat/57-granted-oauth-scopes

Conversation

@Goodyslim

Copy link
Copy Markdown

Closes #57

What

The GitHub dashboard showed the scopes requested at connect time, not the scopes GitHub actually granted. This shows the granted scopes and warns when repo is absent.

Changes

  • app/services/github.py - new GitHubClient.get_granted_scopes() reads the X-OAuth-Scopes response header from GET /user (the token's current grants).
  • app/github/routes.py
    • index() renders the granted scopes (live read preferred, connect-time value as fallback) and a repo_scope_missing flag.
    • callback() prefers the header-reported scopes when storing the account.
    • /github/api/status now includes repo_scope_missing.
  • app/templates/github/index.html - displays granted scopes: ... and shows a role="alert" warning banner with a Reconnect link when repo is missing.

Scopes are informational only; authorization always depends on the token, not on this list (documented on the new method and helper).

Acceptance criteria

  • Granted scopes are fetched from GET /user (and the token-exchange response as a fallback).
  • A warning banner appears when the repo scope is absent.
  • Scopes are never treated as a source of truth for authorization decisions.

Validation

  • pytest tests/test_github_service.py tests/test_github_routes.py -> all pass (adds tests for header parsing, the warning banner, the stored-scopes fallback, and the status flag).
  • ruff check and black --check clean on the changed files.

The dashboard only showed the scopes requested at connect time. Add GitHubClient.get_granted_scopes() (reads the X-OAuth-Scopes header from GET /user) and display the scopes GitHub actually granted, falling back to the scopes captured at connect time. When the granted list is known and omits repo, show a warning banner that private repositories will not load, and expose repo_scope_missing on /github/api/status. Scopes remain informational only and are never used for authorization decisions.

Closes AyinkxLab#57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Show granted OAuth scopes on GitHub dashboard

1 participant