Skip to content

feat(setup): guide setup and bot PAT creation - #402

Open
efraespada wants to merge 13 commits into
developfrom
codex/setup-temporary-github-auth
Open

efraespada wants to merge 13 commits into
developfrom
codex/setup-temporary-github-auth

Conversation

@efraespada

@efraespada efraespada commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

Guided setup now gathers permission-affecting choices before asking for a temporary setup PAT, so GitHub’s prefilled form can reflect the operator’s known needs. A final permission audit still checks authenticated repository and organization state before setup mutations proceed.

What changed

  • Offer guided GitHub PAT creation or manual token entry before requesting the setup credential.
  • Use reviewed setup choices to preview known grants and build a prefilled GitHub PAT link, while identifying grants that depend on remote state.
  • Re-audit the supplied PAT against the completed setup plan; block dependent mutations and provide a corrected link when additional grants are needed.
  • Clarify that GitHub issues and deletes the PAT, repository selection must be made in GitHub, and operators remain responsible for deleting the temporary token.

Review notes

  • The repository specification identifies controlled browser UX, full test-budget evidence, and security review as outstanding readiness gates.

@docs-page

docs-page Bot commented Sep 24, 2026

Copy link
Copy Markdown

To preview the documentation for this pull request, visit the following URL:

docs.page/vypdev/copilot~402

Documentation is deployed and generated using docs.page

@vypbot
vypbot self-requested a review September 24, 2026 16:55
@vypbot vypbot added this to vypdev Sep 24, 2026
@vypbot vypbot moved this to In Progress in vypdev Sep 24, 2026

@vypbot vypbot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current status: All findings originating in this review are resolved.
Last reconciled on 66b9df2. See aggregate Bugbot status.

🤖 Bugbot review snapshot

Bugbot reported 1 potential problem when commit ee61a37 was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.

Findings

  • medium: Use the organization Members form parameter — src/application/policies/setup_pat_creation_url_policy.ts:22

Comment thread src/application/policies/setup_pat_creation_url_policy.ts
@codecov-commenter

codecov-commenter commented Sep 24, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 97.78870% with 9 lines in your changes missing coverage. Please review.
✅ Project coverage is 92.05%. Comparing base (7261967) to head (66b9df2).

Files with missing lines Patch % Lines
src/cli/commands/setup.ts 96.12% 3 Missing and 2 partials ⚠️
src/cli/setup_credential_prompt_adapter.ts 97.14% 1 Missing and 1 partial ⚠️
src/cli/setup_terminal_driver.ts 90.00% 0 Missing and 1 partial ⚠️
src/cli/setup_token_permission_presenter.ts 87.50% 1 Missing ⚠️
Additional details and impacted files
@@             Coverage Diff             @@
##           develop     #402      +/-   ##
===========================================
+ Coverage    91.77%   92.05%   +0.27%     
===========================================
  Files          686      694       +8     
  Lines        20484    20862     +378     
  Branches      5582     5711     +129     
===========================================
+ Hits         18799    19204     +405     
+ Misses         690      667      -23     
+ Partials       995      991       -4     
Files with missing lines Coverage Δ
src/application/policies/setup_journey_policy.ts 100.00% <100.00%> (ø)
...lication/policies/setup_pat_creation_url_policy.ts 100.00% <100.00%> (ø)
...rc/application/policies/setup_pat_intent_policy.ts 100.00% <100.00%> (ø)
...cation/policies/setup_permission_summary_policy.ts 100.00% <100.00%> (ø)
...application/policies/setup_questionnaire_policy.ts 91.35% <100.00%> (+3.04%) ⬆️
...lication/policies/setup_token_permission_policy.ts 99.04% <100.00%> (+1.19%) ⬆️
...plication/usecases/setup/setup_journey_use_case.ts 100.00% <100.00%> (ø)
...pplication/usecases/setup/setup_wizard_use_case.ts 76.28% <100.00%> (+1.56%) ⬆️
...up/verify_guided_workflow_pat_identity_use_case.ts 100.00% <100.00%> (ø)
src/cli/setup_journey_presenter.ts 100.00% <100.00%> (ø)
... and 7 more

... and 4 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@vypbot

vypbot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Bugbot: review complete

Current status: No active findings on 66b9df2.

Pull request · Verified commit · Workflow run

@vypbot vypbot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current status: All findings originating in this review are resolved.
Last reconciled on 66b9df2. See aggregate Bugbot status.

🤖 Bugbot review snapshot

Bugbot reported 1 potential problem when commit 4912384 was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.

Findings

  • low: Incorrectly says fine-grained PATs cannot provide Checks permission — docs/authentication.mdx:45

Comment thread docs/authentication.mdx Outdated

@vypbot vypbot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current status: All findings originating in this review are resolved.
Last reconciled on 66b9df2. See aggregate Bugbot status.

🤖 Bugbot review snapshot

Bugbot reported 1 potential problem when commit 3d797c4 was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.

Findings

  • medium: Projects selection skips the owner-kind question — src/application/policies/setup_pat_intent_policy.ts:28

Comment thread src/application/policies/setup_pat_intent_policy.ts

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Status: In Progress

Development

Successfully merging this pull request may close these issues.

3 participants