feat(setup): guide setup and bot PAT creation - #402
Conversation
|
To preview the documentation for this pull request, visit the following URL:
|
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled ondc7a834. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 1 potential problem when commit ee61a37 was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.
Findings
- medium: Use the organization Members form parameter —
src/application/policies/setup_pat_creation_url_policy.ts:22
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## develop #402 +/- ##
===========================================
+ Coverage 91.77% 92.65% +0.88%
===========================================
Files 686 774 +88
Lines 20484 22667 +2183
Branches 5582 6375 +793
===========================================
+ Hits 18799 21002 +2203
+ Misses 690 602 -88
- Partials 995 1063 +68
🚀 New features to boost your workflow:
|
Bugbot: review complete
|
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled ondc7a834. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 2 potential problems when commit e36729d was analyzed. This snapshot is historical; use the status block above for current state. 2 findings are linked to changed code.
Findings
- medium: No-TTY web setup has no way to obtain the pairing code —
specs/local-web-setup-assistant.md:219 - medium: Every paired tab receives the takeover ticket —
src/cli/web_setup_bridge.ts:34
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled ondc7a834. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 3 potential problems when commit 34264ae was analyzed. This snapshot is historical; use the status block above for current state. 3 findings are linked to changed code.
Findings
- medium: Storage CLI flags are discarded when overrides are merged —
src/cli/setup_command_options.ts:102 - medium: Release and hotfix overrides can be replaced during PAT intent collection —
src/application/policies/setup_pat_intent_policy.ts:12 - low: Unauthenticated requests can lock out the setup session —
specs/local-web-setup-assistant.md:242
…uration with evidence and recovery
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled ondc7a834. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 1 potential problem when commit 1e91f70 was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.
Findings
- low: Web coverage thresholds cannot be met by the configured Jest tests —
jest.config.js:9
…and recover pairing after cooldown
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled ondc7a834. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 3 potential problems when commit 7c4ce04 was analyzed. This snapshot is historical; use the status block above for current state. 3 findings are linked to changed code.
Findings
- medium: Adding a producer can crash when the App ID is numeric —
web/src/components/ProducerSelector.svelte:14 - low: Known GitHub check conclusions are shown as unknown —
web/src/i18n/checkEvidence.ts:4 - low: Sanitize discovered Project titles before printing them in the terminal selector —
src/application/usecases/setup/setup_questionnaire_controller.ts:48
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled ondc7a834. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 2 potential problems when commit 4bc538e was analyzed. This snapshot is historical; use the status block above for current state. 2 findings are linked to changed code.
Findings
- low: Detect default branch changes before applying the reviewed plan —
src/application/policies/setup_remote_facts_policy.ts:8 - low: Text fallback hides discovered Project choices —
src/application/usecases/setup/setup_questionnaire_controller.ts:45
… text-mode projects
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled ondc7a834. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 1 potential problem when commit 87510f0 was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.
Findings
- low: Enter submits invalid pairing codes —
web/src/components/PairingPanel.svelte:21
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled ondc7a834. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 2 potential problems when commit fb358b7 was analyzed. This snapshot is historical; use the status block above for current state. 2 findings are linked to changed code.
Findings
- medium: Project opt-out is overridden by the saved selection —
src/application/usecases/setup/prepare_setup_pat_intent_use_case.ts:74 - low: Permission preview leaves enabled workflows untranslated —
web/src/i18n/messageCopy.ts:20
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled ondc7a834. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 3 potential problems when commit 2eade6a was analyzed. This snapshot is historical; use the status block above for current state. 3 findings are linked to changed code.
Findings
- medium: Storage scope and visibility flags do not override config values —
src/application/policies/merge_setup_overrides_policy.ts:26 - low: Declining Projects still prompts for a Project selection —
src/application/policies/setup_questionnaire_policy.ts:331 - low: Closed Projects can appear as selectable candidates —
src/infrastructure/github_setup_project_discovery_adapter.ts:23
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled ondc7a834. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 2 potential problems when commit 8e64232 was analyzed. This snapshot is historical; use the status block above for current state. 2 findings are linked to changed code.
Findings
- low: Excess-grant comparison is reversed —
src/application/usecases/setup/audit_configured_setup_pat_use_case.ts:51 - low: REST pagination stops after the first page —
src/infrastructure/github_setup_project_discovery_adapter.ts:64
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled ondc7a834. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 1 potential problem when commit 3b23d33 was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.
Findings
- low: Spanish release warning describes installed automation as future work —
web/src/i18n/planWarnings/es.ts:6
…talled automation copy
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled ondc7a834. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 1 potential problem when commit 87edb6c was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.
Findings
- low: Receipt can claim Variables completed when provisioning is unavailable —
src/application/usecases/actions/initial_setup_workflow.ts:159
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled ondc7a834. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 1 potential problem when commit 640d63c was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.
Findings
- low: Background polling clears session errors —
web/src/App.svelte:24
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled ondc7a834. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 4 potential problems when commit 9c1f415 was analyzed. This snapshot is historical; use the status block above for current state. 4 findings are linked to changed code.
Findings
- low: Localization requirement conflicts with the four-language setup scope —
specs/guarded-pull-request-approval-setup-and-doctor.md:264 - low: Spanish guidance incorrectly says Cursor is installed separately —
src/application/policies/setup_question_guidance_policy.ts:44 - low: Spaced retry selections are not recognized —
src/application/usecases/setup/setup_questionnaire_controller.ts:77 - low: Receipt reports completed resource writes when all values were skipped —
src/application/usecases/actions/initial_setup_workflow.ts:144
Adds guided GitHub token setup and an optional local web assistant, helping operators review required permissions and verify credentials before setup changes are applied. The flow keeps token creation and revocation under the operator’s control and reports partial outcomes more accurately.
What changed
copilot setup --web, a loopback-only browser interface with plan review and separate masked inputs for the temporary setup PAT and bot PAT.Validation
Review notes
unverifiableremain unverified until a latercopilot doctoror workflow check.