Skip to content

feat(setup): guide setup and bot PAT creation - #402

Merged
efraespada merged 50 commits into
developfrom
codex/setup-temporary-github-auth
Sep 29, 2026
Merged

efraespada merged 50 commits into
developfrom
codex/setup-temporary-github-auth

Conversation

@efraespada

@efraespada efraespada commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

Adds guided GitHub token setup and an optional local web assistant, helping operators review required permissions and verify credentials before setup changes are applied. The flow keeps token creation and revocation under the operator’s control and reports partial outcomes more accurately.

What changed

  • Collects permission-affecting setup choices before generating a temporary setup token, previews requested grants, and carries answers into the setup wizard.
  • Adds copilot setup --web, a loopback-only browser interface with plan review and separate masked inputs for the temporary setup PAT and bot PAT.
  • Checks GitHub identity, repository access, and token permissions before dependent setup changes; reports grant differences and partial outcomes.
  • Documents token scope, expiration, cleanup, and verification limits across the CLI and web setup flows.

Validation

  • Documentation records a browser prefill check for twelve grants; no token was minted.

Review notes

  • The web assistant cannot prevent browser extensions or other processes under the operator’s OS account from observing a pasted token; assess this local trust boundary.
  • The web flow does not dispatch a credential-health workflow before Apply. Existing optional provider Secrets marked unverifiable remain unverified until a later copilot doctor or workflow check.
  • Confirm the documented manual steps for selecting only the target repository and deleting the temporary setup PAT are clear to operators.

@docs-page

docs-page Bot commented Sep 24, 2026

Copy link
Copy Markdown

To preview the documentation for this pull request, visit the following URL:

docs.page/vypdev/copilot~402

Documentation is deployed and generated using docs.page

@vypbot
vypbot self-requested a review September 24, 2026 16:55
@vypbot vypbot added this to vypdev Sep 24, 2026
@vypbot vypbot moved this to In Progress in vypdev Sep 24, 2026

@vypbot vypbot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current status: All findings originating in this review are resolved.
Last reconciled on dc7a834. See aggregate Bugbot status.

🤖 Bugbot review snapshot

Bugbot reported 1 potential problem when commit ee61a37 was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.

Findings

  • medium: Use the organization Members form parameter — src/application/policies/setup_pat_creation_url_policy.ts:22

Comment thread src/application/policies/setup_pat_creation_url_policy.ts
@codecov-commenter

codecov-commenter commented Sep 24, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 92.65%. Comparing base (7261967) to head (dc7a834).

Additional details and impacted files
@@             Coverage Diff             @@
##           develop     #402      +/-   ##
===========================================
+ Coverage    91.77%   92.65%   +0.88%     
===========================================
  Files          686      774      +88     
  Lines        20484    22667    +2183     
  Branches      5582     6375     +793     
===========================================
+ Hits         18799    21002    +2203     
+ Misses         690      602      -88     
- Partials       995     1063      +68     
Files with missing lines Coverage Δ
...cation/errors/setup_interaction_cancelled_error.ts 100.00% <100.00%> (ø)
...plication/policies/merge_setup_overrides_policy.ts 100.00% <100.00%> (ø)
...c/application/policies/setup_configuration_plan.ts 93.67% <100.00%> (+0.55%) ⬆️
...ication/policies/setup_configuration_validation.ts 63.44% <100.00%> (+5.79%) ⬆️
src/application/policies/setup_journey_policy.ts 100.00% <100.00%> (ø)
...lication/policies/setup_pat_creation_url_policy.ts 100.00% <100.00%> (ø)
...rc/application/policies/setup_pat_intent_policy.ts 100.00% <100.00%> (ø)
...cation/policies/setup_permission_summary_policy.ts 100.00% <100.00%> (ø)
...ication/policies/setup_project_selection_policy.ts 100.00% <100.00%> (ø)
...on/policies/setup_question_documentation_policy.ts 100.00% <100.00%> (ø)
... and 102 more

... and 3 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@vypbot

vypbot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Bugbot: review complete

Current status: No active findings on dc7a834.

Pull request · Verified commit · Workflow run

@vypbot vypbot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current status: All findings originating in this review are resolved.
Last reconciled on dc7a834. See aggregate Bugbot status.

🤖 Bugbot review snapshot

Bugbot reported 2 potential problems when commit e36729d was analyzed. This snapshot is historical; use the status block above for current state. 2 findings are linked to changed code.

Findings

  • medium: No-TTY web setup has no way to obtain the pairing code — specs/local-web-setup-assistant.md:219
  • medium: Every paired tab receives the takeover ticket — src/cli/web_setup_bridge.ts:34

Comment thread specs/local-web-setup-assistant.md Outdated
Comment thread src/cli/web_setup_bridge.ts Outdated

@vypbot vypbot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current status: All findings originating in this review are resolved.
Last reconciled on dc7a834. See aggregate Bugbot status.

🤖 Bugbot review snapshot

Bugbot reported 3 potential problems when commit 34264ae was analyzed. This snapshot is historical; use the status block above for current state. 3 findings are linked to changed code.

Findings

  • medium: Storage CLI flags are discarded when overrides are merged — src/cli/setup_command_options.ts:102
  • medium: Release and hotfix overrides can be replaced during PAT intent collection — src/application/policies/setup_pat_intent_policy.ts:12
  • low: Unauthenticated requests can lock out the setup session — specs/local-web-setup-assistant.md:242

Comment thread src/cli/setup_command_options.ts
Comment thread src/application/policies/setup_pat_intent_policy.ts Outdated
Comment thread specs/local-web-setup-assistant.md Outdated

@vypbot vypbot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current status: All findings originating in this review are resolved.
Last reconciled on dc7a834. See aggregate Bugbot status.

🤖 Bugbot review snapshot

Bugbot reported 1 potential problem when commit 1e91f70 was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.

Findings

  • low: Web coverage thresholds cannot be met by the configured Jest tests — jest.config.js:9

Comment thread jest.config.js

@vypbot vypbot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current status: All findings originating in this review are resolved.
Last reconciled on dc7a834. See aggregate Bugbot status.

🤖 Bugbot review snapshot

Bugbot reported 3 potential problems when commit 7c4ce04 was analyzed. This snapshot is historical; use the status block above for current state. 3 findings are linked to changed code.

Findings

  • medium: Adding a producer can crash when the App ID is numeric — web/src/components/ProducerSelector.svelte:14
  • low: Known GitHub check conclusions are shown as unknown — web/src/i18n/checkEvidence.ts:4
  • low: Sanitize discovered Project titles before printing them in the terminal selector — src/application/usecases/setup/setup_questionnaire_controller.ts:48

Comment thread web/src/components/ProducerSelector.svelte
Comment thread web/src/i18n/checkEvidence.ts Outdated
Comment thread src/application/usecases/setup/setup_questionnaire_controller.ts Outdated

@vypbot vypbot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current status: All findings originating in this review are resolved.
Last reconciled on dc7a834. See aggregate Bugbot status.

🤖 Bugbot review snapshot

Bugbot reported 2 potential problems when commit 4bc538e was analyzed. This snapshot is historical; use the status block above for current state. 2 findings are linked to changed code.

Findings

  • low: Detect default branch changes before applying the reviewed plan — src/application/policies/setup_remote_facts_policy.ts:8
  • low: Text fallback hides discovered Project choices — src/application/usecases/setup/setup_questionnaire_controller.ts:45

Comment thread src/application/policies/setup_remote_facts_policy.ts
Comment thread src/application/usecases/setup/setup_questionnaire_controller.ts Outdated

@vypbot vypbot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current status: All findings originating in this review are resolved.
Last reconciled on dc7a834. See aggregate Bugbot status.

🤖 Bugbot review snapshot

Bugbot reported 1 potential problem when commit 87510f0 was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.

Findings

  • low: Enter submits invalid pairing codes — web/src/components/PairingPanel.svelte:21

Comment thread web/src/components/PairingPanel.svelte

@vypbot vypbot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current status: All findings originating in this review are resolved.
Last reconciled on dc7a834. See aggregate Bugbot status.

🤖 Bugbot review snapshot

Bugbot reported 2 potential problems when commit fb358b7 was analyzed. This snapshot is historical; use the status block above for current state. 2 findings are linked to changed code.

Findings

  • medium: Project opt-out is overridden by the saved selection — src/application/usecases/setup/prepare_setup_pat_intent_use_case.ts:74
  • low: Permission preview leaves enabled workflows untranslated — web/src/i18n/messageCopy.ts:20

Comment thread src/application/usecases/setup/prepare_setup_pat_intent_use_case.ts Outdated
Comment thread web/src/i18n/messageCopy.ts

@vypbot vypbot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current status: All findings originating in this review are resolved.
Last reconciled on dc7a834. See aggregate Bugbot status.

🤖 Bugbot review snapshot

Bugbot reported 3 potential problems when commit 2eade6a was analyzed. This snapshot is historical; use the status block above for current state. 3 findings are linked to changed code.

Findings

  • medium: Storage scope and visibility flags do not override config values — src/application/policies/merge_setup_overrides_policy.ts:26
  • low: Declining Projects still prompts for a Project selection — src/application/policies/setup_questionnaire_policy.ts:331
  • low: Closed Projects can appear as selectable candidates — src/infrastructure/github_setup_project_discovery_adapter.ts:23

Comment thread src/application/policies/merge_setup_overrides_policy.ts
Comment thread src/application/policies/setup_questionnaire_policy.ts
Comment thread src/infrastructure/github_setup_project_discovery_adapter.ts Outdated

@vypbot vypbot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current status: All findings originating in this review are resolved.
Last reconciled on dc7a834. See aggregate Bugbot status.

🤖 Bugbot review snapshot

Bugbot reported 2 potential problems when commit 8e64232 was analyzed. This snapshot is historical; use the status block above for current state. 2 findings are linked to changed code.

Findings

  • low: Excess-grant comparison is reversed — src/application/usecases/setup/audit_configured_setup_pat_use_case.ts:51
  • low: REST pagination stops after the first page — src/infrastructure/github_setup_project_discovery_adapter.ts:64

Comment thread src/infrastructure/github_setup_project_discovery_adapter.ts Outdated

@vypbot vypbot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current status: All findings originating in this review are resolved.
Last reconciled on dc7a834. See aggregate Bugbot status.

🤖 Bugbot review snapshot

Bugbot reported 1 potential problem when commit 3b23d33 was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.

Findings

  • low: Spanish release warning describes installed automation as future work — web/src/i18n/planWarnings/es.ts:6

Comment thread web/src/i18n/planWarnings/es.ts Outdated

@vypbot vypbot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current status: All findings originating in this review are resolved.
Last reconciled on dc7a834. See aggregate Bugbot status.

🤖 Bugbot review snapshot

Bugbot reported 1 potential problem when commit 87edb6c was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.

Findings

  • low: Receipt can claim Variables completed when provisioning is unavailable — src/application/usecases/actions/initial_setup_workflow.ts:159

Comment thread src/application/usecases/actions/initial_setup_workflow.ts Outdated

@vypbot vypbot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current status: All findings originating in this review are resolved.
Last reconciled on dc7a834. See aggregate Bugbot status.

🤖 Bugbot review snapshot

Bugbot reported 1 potential problem when commit 640d63c was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.

Findings

  • low: Background polling clears session errors — web/src/App.svelte:24

Comment thread web/src/App.svelte

@vypbot vypbot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current status: All findings originating in this review are resolved.
Last reconciled on dc7a834. See aggregate Bugbot status.

🤖 Bugbot review snapshot

Bugbot reported 4 potential problems when commit 9c1f415 was analyzed. This snapshot is historical; use the status block above for current state. 4 findings are linked to changed code.

Findings

  • low: Localization requirement conflicts with the four-language setup scope — specs/guarded-pull-request-approval-setup-and-doctor.md:264
  • low: Spanish guidance incorrectly says Cursor is installed separately — src/application/policies/setup_question_guidance_policy.ts:44
  • low: Spaced retry selections are not recognized — src/application/usecases/setup/setup_questionnaire_controller.ts:77
  • low: Receipt reports completed resource writes when all values were skipped — src/application/usecases/actions/initial_setup_workflow.ts:144

Comment thread specs/guarded-pull-request-approval-setup-and-doctor.md Outdated
Comment thread src/application/policies/setup_question_guidance_policy.ts Outdated
Comment thread src/application/usecases/setup/setup_questionnaire_controller.ts Outdated
Comment thread src/application/usecases/actions/initial_setup_workflow.ts Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants