Skip to content

Fix Artifacts session repo git auth - #213

Merged
kentcdodds merged 2 commits into
mainfrom
cursor/session-repo-push-failure-fab1
Apr 19, 2026
Merged

kentcdodds merged 2 commits into
mainfrom
cursor/session-repo-push-failure-fab1

Conversation

@kentcdodds

@kentcdodds kentcdodds commented Apr 18, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • stop passing Artifacts tokens through @cloudflare/shell's token option on repo-session clone/pull/push paths
  • centralize Artifacts git credentials in a helper that always uses username x with the token secret as the password
  • add focused regression tests for the helper and the repo-session publish/rebase git auth flow

Testing

  • npx vitest run --project node-unit packages/worker/src/repo/artifacts.node.test.ts packages/worker/src/repo/repo-session-do.node.test.ts
  • npm run typecheck

Notes

  • I verified in the installed dependency (node_modules/@cloudflare/shell/dist/git/index.js) that passing token to push/pull rewrites auth to username=<token>, password=x-oauth-basic, which is incompatible with Artifacts' x:<tokenSecret> auth shape and explains the 401s on session-repo pushes.
  • A live Artifacts git push smoke test was not possible in this environment because CLOUDFLARE_ACCOUNT_ID, CLOUDFLARE_API_TOKEN, and CLOUDFLARE_API_BASE_URL are unset here.
Open in Web Open in Cursor 

Summary by CodeRabbit

Release Notes

  • Tests

    • Added comprehensive test coverage for artifact token parsing and Git authentication credential construction.
    • Added integration tests verifying Git operations use proper authentication with credentials derived from artifact tokens.
  • Refactor

    • Consolidated Git authentication logic into a shared helper for consistent credential construction across all Git operations.
    • Simplified Git operations (clone, push, pull) to use unified authentication handling.

Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
@coderabbitai

coderabbitai Bot commented Apr 18, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 5d979ad5-f41a-4211-936f-4d833f7d6f3b

📥 Commits

Reviewing files that changed from the base of the PR and between 2d191ab and ba128d2.

📒 Files selected for processing (4)
  • packages/worker/src/repo/artifacts.node.test.ts
  • packages/worker/src/repo/artifacts.ts
  • packages/worker/src/repo/repo-session-do.node.test.ts
  • packages/worker/src/repo/repo-session-do.ts

📝 Walkthrough

Walkthrough

This PR refactors Git authentication credential construction by introducing a new buildArtifactsGitAuth helper function that standardizes parsing artifact tokens and deriving username/password credentials. The function is integrated into buildAuthenticatedArtifactsRemote and git operations throughout the repository session handler, with comprehensive test coverage added.

Changes

Cohort / File(s) Summary
Artifact Auth Helper
packages/worker/src/repo/artifacts.ts, packages/worker/src/repo/artifacts.node.test.ts
Added new exported buildArtifactsGitAuth function that constructs Git credentials (username: 'x' and derived password) from artifact tokens. Updated buildAuthenticatedArtifactsRemote to delegate credential construction to this new helper instead of parsing tokens inline.
Git Session Refactoring
packages/worker/src/repo/repo-session-do.ts
Refactored git operations (clone, push, pull) and remote configuration to use buildArtifactsGitAuth for credential handling. Removed manual token parsing and inline username/password assignment.
Git Session Test Suite
packages/worker/src/repo/repo-session-do.node.test.ts
Added comprehensive test file with fully mocked RepoSession environment including git state (branch, commits, remotes) and in-memory git operations. Tests verify rebaseSession and publishSession correctly use Artifacts username/password authentication without exposing raw tokens in git options.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Possibly related PRs

  • kentcdodds/kody#200: Modifies the same artifact token parsing and Git credential construction codepaths in artifacts.ts and repo auth handling.
  • kentcdodds/kody#191: Updates authentication and token parsing in artifacts.ts and related repo credential consumption logic.

Poem

🐰 A helper born from repetition's call,
To parse tokens once, not twice at all,
With username: x and passwords clean,
Git auth flows smoother than ever seen! ✨

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title 'Fix Artifacts session repo git auth' directly summarizes the main change: fixing git authentication handling for Artifacts session repos by centralizing credentials and removing problematic token passing.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/session-repo-push-failure-fab1

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
@kentcdodds
kentcdodds marked this pull request as ready for review April 19, 2026 00:03
@github-actions

Copy link
Copy Markdown
Contributor

🔎 Preview deployed: https://kody-pr-213.kentcdodds.workers.dev

Worker: kody-pr-213
D1: kody-pr-213-db
KV: kody-pr-213-oauth-kv

Mocks:

@kentcdodds
kentcdodds merged commit 3404ff6 into main Apr 19, 2026
16 checks passed
@kody-bot
kody-bot deleted the cursor/session-repo-push-failure-fab1 branch April 30, 2026 23:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants