Skip to content

Let the team-mode buddy manage a project's GitHub repositories - #256

Draft
LinseCed wants to merge 3 commits into
feature/228-content-structure-actionsfrom
feature/229-github-sources-actions
Draft

LinseCed wants to merge 3 commits into
feature/228-content-structure-actionsfrom
feature/229-github-sources-actions

Conversation

@LinseCed

@LinseCed LinseCed commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Related issue

Part of #229 (GitHub slice only; the issue stays open)

Short summary

Adds the GitHub half of the sources area of the team-mode buddy: a manager can see which GitHub tokens they have stored, browse what GitHub lists for an owner, see what the project has connected, and connect, link, unlink and sync repositories. Every write is a stored proposal the manager confirms.

  • Three reads: list_my_credential_names (GitHub tokens only for now), discover_repositories, list_project_sources.
  • Four actions: connect_repositories (bulk), link_repository (standard), unlink_repository (destructive), sync_repository (bulk).
  • New published GithubSourcesApi in the connector module wrapping the services the REST controllers call, always with the caller's own authId. Onboarding may only import external, and none of this was published before.
  • Credentials are names only. No tool parameter takes a token, and a token_name shaped like a GitHub token is refused without being repeated in the refusal, the preview or the stored proposal.
  • Sync and unlink are only offered for a repository linked to the turn's project, and every preview says how many other projects share the repository.

Checks

  • I verified the code makes sense intuitively
  • The PR changes affect only this issue, no unrelated/unwanted code changes to other modules/code segments
  • CI runs (./gradlew clean build, keycloack)
  • New business logic is unit tested, including WebMvcTest for api controllers
  • The new functionality is tested manually

Additional notes

  • Draft, stacked on Let the team-mode buddy manage the onboarding content of a project's members #255 (base feature/228-content-structure-actions), which is stacked on Let the team-mode buddy manage who is on a project and what they do #254. Merge order is Let the team-mode buddy manage who is on a project and what they do #254, Let the team-mode buddy manage the onboarding content of a project's members #255, then this; after that change the base to dev. The diff then shows only this PR's two commits: the published API with its adapter, then the tools and actions.
  • CI: the build was still running when this was written, so that box is unchecked. ./gradlew clean check passed locally: 3601 tests, 0 failures.
  • Deviations from the issue: previews give a count of other projects, not their names (there is no published project-name lookup, and naming other projects to a manager would leak them); discover_repositories takes an explicit kind (organisation or user); discover_repositories blocks a request thread while GitHub answers, because the tool interface is not suspending.
  • Link: offered for any connected repository. GitHub is asked whether the manager can see it when they confirm (draft cannot call GitHub), as the REST endpoint does, and the preview says so. The turn is already confirmed as the project's manager, so a plain project member cannot do this through the buddy; REST accepts any member.
  • Checked rather than assumed: GithubUpdatesService.updateRepository is not transactional; a probe test shows a connection loaded with no session still has the snapshot and token a sync reads.
  • Not covered: nothing talks to a real GitHub, and the connector services are mocked at the adapter boundary. Jira, Confluence, source toggles and uploads are separate PRs.
  • Not tested manually.

🤖 Generated with Claude Code

LinseCed and others added 2 commits September 21, 2026 16:25
The team-mode buddy needs to connect, link, unlink and sync repositories and
read a manager's token names, but none of that was reachable from outside the
connector: only read-only lookups were published, and onboarding may only
import a module's `external` package.

GithubSourcesApi wraps the services the REST controllers already call, with
the caller's authId throughout, since GitHub access here is always the
caller's own. It returns and accepts token names, never token values.
Connecting is per repository, so one failing does not stop or hide the
others. Linking asks whether the caller can see the repository before it links,
as the REST endpoint does, and the connector's own exceptions become
ResponseStatusExceptions with messages safe to show a person.

Also adds a regression test that a connection loaded with no session still has
the snapshot and token a sync reads, because updateRepository is not
transactional and the buddy calls it without the request session REST has.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
First slice of the sources area (backend#229): list_my_credential_names,
discover_repositories, list_project_sources, and the actions
connect_repositories (bulk), link_repository, unlink_repository (destructive)
and sync_repository (bulk). Jira, Confluence, source toggles and uploads follow
separately.

A repository is one connection however many projects use it, so a sync or an
unlink reaches past the turn's project. Both are only offered for a repository
linked to the turn's project, and every preview says how many other projects
share it and what that means for them. A link is offered for any connected
repository and GitHub is asked whether the manager can see it when they confirm.

Credentials are names only. No tool parameter accepts a token, the tool
descriptions tell the model to refuse one pasted into the conversation, and a
token name shaped like a GitHub token is refused without being repeated in the
refusal, the preview or the stored proposal. The preview of a connect says the
new repository keeps using the manager's token for its nightly updates.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant