Skip to content

GitHubDeviceFlow has never run against real GitHub: its JSON request bodies and 200-with-error polling are untested live #166

Description

@matt-edmondson

Plan item

  • Plan: https://github.com/ktsu-dev/GitIntegration/blob/e93880ebdc96f46adf780d97fbc211564ea56d4a/docs/superpowers/plans/2026-09-21-worktrees-and-github-auth.md#L2430-L2434
  • Spec: https://github.com/ktsu-dev/GitIntegration/blob/e93880ebdc96f46adf780d97fbc211564ea56d4a/docs/superpowers/specs/2026-09-21-worktrees-and-github-auth-design.md#L339-L347

The OAuth App does not exist yet. Every test here runs against a fake transport, so no task is blocked. But nothing has been confirmed against GitHub itself, and it cannot be until someone with organization ownership registers an OAuth App with device flow enabled and approves it for SAML single sign-on, scopes repo and read:org.

PR #118 only mentioned this as a "Not yet verified end to end" paragraph in its description. No issue tracks it.

What exists today

  • GitIntegration/Hosting/GitHubDeviceFlow.cs implements RequestDeviceCodeAsync and WaitForTokenAsync over a raw HttpClient.
  • GitIntegration.Test/Hosting/GitHubDeviceFlowTests.cs has about 18 tests, all against FakeHttpMessageHandler.

What's missing, and why it matters

These assumptions have only been checked against the project's reading of the protocol, never against GitHub:

  • JSON request bodies. The type's own remarks (GitHubDeviceFlow.cs, around L100) say both endpoints are sent JSON "even though GitHub's own published documentation shows the device flow using form-url-encoded requests". If GitHub stops accepting JSON, every sign-in fails, and no fake-transport test can catch that.
  • Errors in a 200 body. The code assumes GitHub reports authorization_pending, slow_down, access_denied and expired_token in the body of a 200 response.
  • SAML SSO. Nobody has confirmed that the resulting token can be approved for SAML single sign-on on the target organization.

Acceptance criteria

  • An organization owner registers a GitHub OAuth App with device flow enabled (scopes repo and read:org) and approves it for SAML SSO.
  • A manual run, or an opt-in run gated on credentials, completes RequestDeviceCodeAsync followed by WaitForTokenAsync against github.com. It records what actually happens for pending, slow_down (if it can be provoked), denial, and success.
  • With the token that run obtains, GitHubProvider.GetRepositoriesAsync lists the organization's private repositories.
  • The findings are recorded in docs/superpowers/research/, the way 2026-08-21-azure-devops-rest-findings.md records the Azure DevOps ones. If the JSON-body assumption fails, the requests are switched to form encoding.

Dependencies

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions