Prevent unscoped GitHub task queries for SSH repos (#2506)

* fix: prevent unscoped ssh github task queries

Co-authored-by: Orca <help@stably.ai>

* test: update worktree card context menu mock

Co-authored-by: Orca <help@stably.ai>

---------

Co-authored-by: Orca <help@stably.ai>
This commit is contained in:
Jinwoo Hong
2026-05-21 04:23:59 -04:00
committed by GitHub
co-authored by Orca
parent 9adf9058e9
commit fbf53aa4cc
3 changed files with 80 additions and 28 deletions
+25 -1
View File
@@ -36,7 +36,8 @@ vi.mock('./gh-utils', () => ({
repoPath,
connectionId: connectionId ?? null
}),
ghRepoExecOptions: (context: { repoPath: string }) => ({ cwd: context.repoPath }),
ghRepoExecOptions: (context: { repoPath: string; connectionId?: string | null }) =>
context.connectionId ? {} : { cwd: context.repoPath },
getOwnerRepo: getOwnerRepoMock,
getIssueOwnerRepo: getIssueOwnerRepoMock,
getOwnerRepoForRemote: getOwnerRepoForRemoteMock,
@@ -548,4 +549,27 @@ describe('listWorkItems', () => {
}
])
})
it('rejects unresolved SSH repositories without running unscoped GitHub work-item queries', async () => {
getIssueOwnerRepoMock.mockResolvedValue(null)
getOwnerRepoMock.mockResolvedValue(null)
getOwnerRepoForRemoteMock.mockResolvedValue(null)
await expect(
listWorkItems('/remote/repo', 10, undefined, undefined, undefined, 'ssh-1')
).rejects.toThrow('GitHub work items require a GitHub remote for SSH repositories')
expect(ghExecFileAsyncMock).not.toHaveBeenCalled()
ghExecFileAsyncMock.mockClear()
getIssueOwnerRepoMock.mockResolvedValue(null)
getOwnerRepoMock.mockResolvedValue(null)
getOwnerRepoForRemoteMock.mockResolvedValue(null)
await expect(
listWorkItems('/remote/repo', 10, 'is:open', undefined, undefined, 'ssh-1')
).rejects.toThrow('GitHub work items require a GitHub remote for SSH repositories')
expect(ghExecFileAsyncMock).not.toHaveBeenCalled()
})
})