Skip to content

Refresh gh login from the Git credential store - #40

Merged
akan72 merged 3 commits into
mainfrom
akan72/gh-auth-refresh
Sep 8, 2026
Merged

akan72 merged 3 commits into
mainfrom
akan72/gh-auth-refresh

Conversation

@akan72

@akan72 akan72 commented Aug 27, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Keep the SCP-plus-manual-refresh workflow for reusing a Git PAT with the GitHub CLI, without browser sign-in.
  • Store gh configuration at $HOME/.config/gh, outside the dotfiles checkout. Set GH_CONFIG_DIR in shared bash/zsh configuration and in the refresh script itself so direct SSH invocation selects the same location.
  • Resolve the conflict with the merged shared-shell cleanup. Document explicit environment setup for jobs that do not source shell configuration; leave Git credential routing and old configuration untouched.
  • Add a synthetic-credential regression test to CI. The refresh helper remains human-run by default; the owner explicitly authorized the real mini validation below.

Test Plan

  • Watched sh tests/gh-auth-refresh.sh fail before the fix because the refresh subprocess had no GH_CONFIG_DIR; it passes after the fix locally and on the Mac mini.
  • The regression test executes the actual refresh script with a synthetic credential and stubbed external login, and sources shared.sh under bash and zsh. It verifies the external config path and that no checkout-local gh directory is created.
  • Ran bash -n bashrc shared.sh scripts/gh-auth-refresh.sh tests/gh-auth-refresh.sh, git diff --check, and pre-commit run --all-files: passed.
  • Real Mac mini validation, explicitly owner-authorized: ran the updated refresh helper with GH_TOKEN and GITHUB_TOKEN unset, XDG_CONFIG_HOME="$HOME/dotfiles", and script output suppressed. Exit status was zero. No PAT was displayed or copied to this host.
  • In a separate invocation, ran GH_CONFIG_DIR="$HOME/.config/gh" gh api user --jq .login and gh repo view akan72/dotfiles --json nameWithOwner --jq .nameWithOwner, again with token environment overrides unset: returned akan72 and akan72/dotfiles.
  • Mini validation scripts retained at /tmp/dotfiles-pr40.uDmh1V. This host's live configuration was not changed. Old repository-local gh configuration was not deleted.
  • Screenshots: not applicable; this is a CLI-only change.

@akan72

akan72 commented Sep 8, 2026

Copy link
Copy Markdown
Owner Author

Validation complete for 6cbbfe1: all eight CI jobs passed (plus Dependabot validation): https://github.com/akan72/dotfiles/actions/runs/34261417566. Real PAT refresh on the Mac mini succeeded with output suppressed; independent gh API calls using $HOME/.config/gh authenticated as akan72 and accessed akan72/dotfiles. Synthetic regression tests passed locally and on the mini. Full commands and scope are documented in the Test Plan. PR is left open for merge.

@akan72
akan72 merged commit 1d2741b into main Sep 8, 2026
9 checks passed
@akan72
akan72 deleted the akan72/gh-auth-refresh branch September 8, 2026 18:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant