Skip to content

fix: restore GitHub access onboarding for empty repository lists - #53

Merged
CountableNewt merged 7 commits into
devfrom
feature/mcp-13-github-access
Sep 30, 2026
Merged

CountableNewt merged 7 commits into
devfrom
feature/mcp-13-github-access

Conversation

@CountableNewt

@CountableNewt CountableNewt commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

When GitHub returns no accessible repositories, the connection picker now offers Configure GitHub Access and Refresh Repositories. The access action uses the authenticated project-scoped install flow and returns to the project's Repo tab.

Installation callbacks now reopen the picker without a prior selection and refresh even a fresh cached empty repository list. Selected-repository/409 recovery preserves the chosen branch and now validates the backend’s real same-origin installer URL against the exact origin, endpoint, and project; foreign origins, paths, projects, duplicate parameters, and credentials are rejected. The project page also mounts Repo for legacy callbacks that omit a tab, and callback cleanup preserves that tab.

Validation: frontend empty/error/retry, cache refresh, selected-repository/409 recovery, and real project-tab callback tests; backend unauthenticated/foreign-project rejection and owned-project installation without repository selection. Local validation passed: 182 frontend tests, types, lint (two unrelated warnings tracked as MCP-15), Next 16.3.6 build, 217 Swift tests, and Swift release build with warnings treated as errors. Hosted CI runs on the final head. Development deployment and authenticated browser acceptance will be recorded after merging to dev, before Production promotion.

No permission scope or backend production behavior changes. GitHub still controls which repositories the user grants access to.

Closes #38. Linear: MCP-13.

Resume and refresh the repository catalog after installation even when no repository was selected, so first-time users can grant access and continue onboarding.
Protect the empty repository picker path with session and tenant checks before an installation intent can be created, including installation without a selected repository.
Provide the authenticated installer an absolute project return target, mount the Repo tab for legacy callbacks, and preserve the chosen branch when resuming. Cover the real project page and refreshed catalog flow.
@linear-code

linear-code Bot commented Sep 30, 2026

Copy link
Copy Markdown

MCP-13

The connect-repo conflict response points to the frontend installer rather than GitHub directly. Allow that exact same-origin endpoint for the current project while rejecting foreign origins, paths, duplicate project parameters, and userinfo; exercise the actual backend response shape.
@CountableNewt
CountableNewt merged commit da7859f into dev Sep 30, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant