Skip to content

fix(session): prefer API keys over GitHub tokens - #486

Merged
KNiepok merged 1 commit into
mainfrom
fix/prefer-api-key-over-github-token
Sep 8, 2026
Merged

KNiepok merged 1 commit into
mainfrom
fix/prefer-api-key-over-github-token

Conversation

@KNiepok

@KNiepok KNiepok commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

Description

GitHub personal access tokens are being retired as an authentication method (a PAT belongs to no OAuth application, so Spacelift cannot verify it was issued for Spacelift). Backend side: spacelift-io/backend#17064.

Env auth order changes from token → github → apikey to token → apikey → github.

Today a caller who adds API key variables to migrate only lands on them by accident: the PAT is tried first, fails, and the loop falls through on error (from_environment.go:75-77). Every invocation burns a failed exchange. After this, adding an API key just works.

This changes documented precedence for anyone setting both, so it is a behaviour change rather than a silent fix. SPACELIFT_API_PREFERRED_METHOD is unaffected, it bypasses the ordering entirely.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

@upwind-code-us

upwind-code-us Bot commented Sep 8, 2026

Copy link
Copy Markdown

Upwind Upwind Code Scan - 🔍 Scan in progress…

Upwind is scanning this PR. Results will appear here when the scan completes.

@upwind-code-us

upwind-code-us Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

Upwind Upwind IaC Scan - 🔍 Scan in progress…

Upwind is scanning this PR. Results will appear here when the scan completes.

GitHub personal access tokens are being retired as an authentication
method, because a PAT belongs to no OAuth application and so cannot be
attributed to Spacelift.

With github ahead of apikey, a caller who sets API key variables while
migrating only lands on them by accident: the PAT is attempted first,
fails, and the loop falls through on error. Every invocation burns a
failed exchange, and the migration depends on error handling rather than
on the credential that was added. Swapping the order makes adding an API
key take effect directly.

Error reporting no longer depends on that order either. It used to
return whichever error came last, which happened to be the API key one
only because apikey was tried last; reordering made a half-configured
API key report a missing GitHub token instead. All failures are joined,
so the reason the caller needs is present regardless of order.

This changes documented precedence for callers that set both, so it is a
behaviour change, not a silent fix. SPACELIFT_API_PREFERRED_METHOD is
unaffected: it bypasses the ordering entirely.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@KNiepok
KNiepok force-pushed the fix/prefer-api-key-over-github-token branch from e39c20e to 47f5a2a Compare September 8, 2026 10:54
@KNiepok
KNiepok marked this pull request as ready for review September 8, 2026 11:00
@KNiepok
KNiepok requested a review from a team as a code owner September 8, 2026 11:00
@KNiepok
KNiepok merged commit 7415dfd into main Sep 8, 2026
7 of 9 checks passed
@KNiepok
KNiepok deleted the fix/prefer-api-key-over-github-token branch September 8, 2026 11:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants