Conversation
The team-mode buddy needs to connect, link, unlink and sync repositories and read a manager's token names, but none of that was reachable from outside the connector: only read-only lookups were published, and onboarding may only import a module's `external` package. GithubSourcesApi wraps the services the REST controllers already call, with the caller's authId throughout, since GitHub access here is always the caller's own. It returns and accepts token names, never token values. Connecting is per repository, so one failing does not stop or hide the others. Linking asks whether the caller can see the repository before it links, as the REST endpoint does, and the connector's own exceptions become ResponseStatusExceptions with messages safe to show a person. Also adds a regression test that a connection loaded with no session still has the snapshot and token a sync reads, because updateRepository is not transactional and the buddy calls it without the request session REST has. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
First slice of the sources area (backend#229): list_my_credential_names, discover_repositories, list_project_sources, and the actions connect_repositories (bulk), link_repository, unlink_repository (destructive) and sync_repository (bulk). Jira, Confluence, source toggles and uploads follow separately. A repository is one connection however many projects use it, so a sync or an unlink reaches past the turn's project. Both are only offered for a repository linked to the turn's project, and every preview says how many other projects share it and what that means for them. A link is offered for any connected repository and GitHub is asked whether the manager can see it when they confirm. Credentials are names only. No tool parameter accepts a token, the tool descriptions tell the model to refuse one pasted into the conversation, and a token name shaped like a GitHub token is refused without being repeated in the refusal, the preview or the stored proposal. The preview of a connect says the new repository keeps using the manager's token for its nightly updates. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
5 tasks
…-github-sources-actions
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Related issue
Part of #229 (GitHub slice only; the issue stays open)
Short summary
Adds the GitHub half of the sources area of the team-mode buddy: a manager can see which GitHub tokens they have stored, browse what GitHub lists for an owner, see what the project has connected, and connect, link, unlink and sync repositories. Every write is a stored proposal the manager confirms.
list_my_credential_names(GitHub tokens only for now),discover_repositories,list_project_sources.connect_repositories(bulk),link_repository(standard),unlink_repository(destructive),sync_repository(bulk).GithubSourcesApiin the connector module wrapping the services the REST controllers call, always with the caller's ownauthId. Onboarding may only importexternal, and none of this was published before.token_nameshaped like a GitHub token is refused without being repeated in the refusal, the preview or the stored proposal.Checks
Additional notes
feature/228-content-structure-actions), which is stacked on Let the team-mode buddy manage who is on a project and what they do #254. Merge order is Let the team-mode buddy manage who is on a project and what they do #254, Let the team-mode buddy manage the onboarding content of a project's members #255, then this; after that change the base todev. The diff then shows only this PR's two commits: the published API with its adapter, then the tools and actions../gradlew clean checkpassed locally: 3601 tests, 0 failures.discover_repositoriestakes an explicitkind(organisation or user);discover_repositoriesblocks a request thread while GitHub answers, because the tool interface is not suspending.draftcannot call GitHub), as the REST endpoint does, and the preview says so. The turn is already confirmed as the project's manager, so a plain project member cannot do this through the buddy; REST accepts any member.GithubUpdatesService.updateRepositoryis not transactional; a probe test shows a connection loaded with no session still has the snapshot and token a sync reads.🤖 Generated with Claude Code