Authenticate GitHub API metadata requests when a token is available - #173
Merged
Merged
Conversation
Unauthenticated GitHub REST calls are limited to 60 requests per hour per IP, so a full setup or sqrbx-update on a shared NAT or CI runner can fail with HTTP 403. _sb_gh_api_get now optionally authenticates using GH_TOKEN, then GITHUB_TOKEN, then an already-authenticated gh CLI (resolved lazily once per shell, default API base only, never prompting). The Authorization header is sent only to the configured HTTPS SB_GITHUB_API_BASE, passed to curl through a stdin config so the token never appears in argv, and is never logged or cached. HTTP 401 drops the token and retries once unauthenticated; an unauthenticated 403/429 now suggests GH_TOKEN or gh auth login. Fail-closed metadata handling is unchanged. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts: # SECURITY.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Unauthenticated GitHub REST calls are limited to 60 requests/hour/IP, so a full
setup.shorsqrbx-updatebehind a shared NAT or CI can fail with HTTP 403. All in-Box API calls (tool releases, LazyVim / Oh My Zsh / PowerShell lookups insetup.sh) go through_sb_gh_api_getinscripts/lib/tool-lib.sh, which now optionally authenticates.GH_TOKEN, thenGITHUB_TOKEN, thengh auth token. Theghstep runs only whenghis installed and already logged in, and only for the defaulthttps://api.github.combase. It runs lazily, at most once per shell, withGH_PROMPT_DISABLED=1and stdin from/dev/null, so it never prompts.Authorization: Beareris sent only when the URL is under the configuredSB_GITHUB_API_BASEand that base ishttps://. Artifact downloads never get the header. curl does not forward a customAuthorizationheader to a different host when following a redirect, and we don't pass--location-trusted.curl -K - ... <<<'header = "..."'). Tokens must match^[A-Za-z0-9_.-]+$, so the value can't inject curl config. A malformed token is ignored with a warning that does not print it.GH_TOKENorgh auth login.install.shandinstall.ps1are unchanged.README (Update section) and SECURITY.md (Download trust) are updated.
Tests
New cases in
tests/test-tool-lib.shuse a mock curl that records argv and stdin config. They cover:GH_TOKENis setGITHUB_TOKENis used whenGH_TOKENis unsetghis not consulted for a custom basegh auth tokenfallback is resolved onceThe full host suite (19 files) passes, both with
GH_TOKENunset and with it set.🤖 Generated with Claude Code