Skip to content

Honor configured protocol for automatic repository clones#4205

Draft
MisterJimson wants to merge 3 commits into
pingdotgg:mainfrom
MisterJimson:jason/codex/honor-github-clone-protocol
Draft

Honor configured protocol for automatic repository clones#4205
MisterJimson wants to merge 3 commits into
pingdotgg:mainfrom
MisterJimson:jason/codex/honor-github-clone-protocol

Conversation

@MisterJimson

@MisterJimson MisterJimson commented Jul 20, 2026

Copy link
Copy Markdown

Summary

  • keep the default Create & Clone flow protocol-aware instead of hardcoding a concrete clone URL
  • honor GitHub CLI's per-host git_protocol setting for automatic clones
  • preserve explicit HTTPS and SSH behavior, using HTTPS as the safe fallback when a provider cannot report a preference
  • add focused web, GitHub CLI, and repository-service regression coverage

Why

The Create & Clone UI passed repository.sshUrl directly to the clone operation, bypassing the existing auto protocol path. Remote servers authenticated with gh over HTTPS but without a GitHub SSH key therefore failed to clone private repositories even though HTTPS access was valid.

The UI now submits the provider and repository identity with protocol: "auto". For GitHub, repository lookup reads gh config get git_protocol --host <host> and carries that preference into clone selection. A reported SSH preference still uses SSH, a reported HTTPS preference uses HTTPS, and an unavailable preference falls back to HTTPS instead of recreating the original authentication failure.

Explicit URL clones remain unchanged.

Fixes #4203.

Testing

  • vp test run apps/server/src/sourceControl/GitHubCli.test.ts apps/server/src/sourceControl/SourceControlRepositoryService.test.ts apps/web/src/components/CommandPalette.logic.test.ts (22 tests passed)
  • pnpm --filter @t3tools/contracts typecheck
  • pnpm --filter t3 typecheck
  • pnpm --filter @t3tools/web typecheck

An isolated UI smoke-test startup was attempted, but this nightly checkout's Vite+ dev server is independently blocked by Tsconfig not found @tsconfig/node24/tsconfig.json.

@github-actions github-actions Bot added the vouch:unvouched PR author is not yet trusted in the VOUCHED list. label Jul 20, 2026
@coderabbitai

coderabbitai Bot commented Jul 20, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: e3ec3965-bb4b-4c08-afe3-3e7a02204a3f

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added the size:S 10-29 changed lines (additions + deletions). label Jul 20, 2026
@MisterJimson
MisterJimson marked this pull request as ready for review July 20, 2026 20:37
@macroscopeapp

macroscopeapp Bot commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

This PR changes runtime behavior for repository clone protocol selection across multiple system layers. A high-severity unresolved comment identifies a potential issue where clones may default to SSH unexpectedly, causing authentication failures.

You can customize Macroscope's approvability policy. Learn more.

@MisterJimson MisterJimson changed the title Use HTTPS for automatic repository clones Honor configured protocol for automatic repository clones Jul 21, 2026
@MisterJimson
MisterJimson marked this pull request as draft July 21, 2026 14:03
@github-actions github-actions Bot added size:M 30-99 changed lines (additions + deletions). and removed size:S 10-29 changed lines (additions + deletions). labels Jul 21, 2026

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want fixes drafted automatically? Bugbot Autofix can create code changes for findings. A team admin can enable Autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 2dc2225. Configure here.

return urls.url;
case "ssh":
case "auto":
return urls.preferredProtocol === "https" ? urls.url : urls.sshUrl;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto clone falls back to SSH

High Severity

The selectRemoteUrl's auto protocol choice now defaults to SSH if preferredProtocol is not HTTPS or is missing. This preferredProtocol is frequently unset (e.g., for non-GitHub repos, gh config get failures, or createRepository output). Since getCloneSourceInput always sends protocol: "auto" for looked-up repos, clones often default to SSH despite an HTTPS preference or displayed URL, causing authentication failures.

Additional Locations (2)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 2dc2225. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M 30-99 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Auto clone selects SSH despite gh configured for HTTPS

1 participant