auth

package
v1.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: MIT Imports: 16 Imported by: 0

Documentation

Index

Constants

View Source
const (
	CopilotClientID = "Ov23li8tweQw6odWQebz"
)

Variables

This section is empty.

Functions

func CanOpenBrowser added in v0.700.0

func CanOpenBrowser() bool

func CheckCopilotModelsAPI

func CheckCopilotModelsAPI(token, baseURL string) error

CheckCopilotModelsAPI verifies that the Copilot models API endpoint is reachable using the provided bearer token and base URL.

func CopilotAPIBaseURL

func CopilotAPIBaseURL(enterpriseURL string) string

func CopilotDeviceFlowInstructions

func CopilotDeviceFlowInstructions(deviceCode CopilotDeviceCode) string

func CopilotSessionFilePath

func CopilotSessionFilePath() (string, error)

func CopilotTokenExchangeDisabled added in v0.644.0

func CopilotTokenExchangeDisabled() bool

CopilotTokenExchangeDisabled reports whether the user opted out of the token exchange, forcing the legacy behaviour of sending the raw OAuth token.

func DeleteCopilotSession

func DeleteCopilotSession() error

func IsCopilotAPIToken added in v0.644.0

func IsCopilotAPIToken(token string) bool

IsCopilotAPIToken reports whether the token already is an exchanged Copilot API token (they are opaque "tid=...;exp=..." strings) rather than a GitHub OAuth token. Exchanging one of these again is not possible.

func LoadGitHubOAuthToken

func LoadGitHubOAuthToken() (string, error)

func NormalizeGitHubDomain

func NormalizeGitHubDomain(value string) string

func OpenBrowser

func OpenBrowser(url string) error

func ResolveCopilotAPIAccess added in v0.644.0

func ResolveCopilotAPIAccess(ctx context.Context, token, enterpriseURL, configuredBaseURL string) (string, string)

ResolveCopilotAPIAccess returns the bearer token and API base URL to use for Copilot requests. It exchanges the GitHub OAuth token for a Copilot API token so that organization BYOK custom models become visible, and falls back to the supplied token and base URL when the exchange is unavailable.

configuredBaseURL, when non-empty, always wins: an explicitly configured host must not be silently replaced by the one advertised by GitHub.

func SaveCopilotSession

func SaveCopilotSession(session CopilotSession) error

func ValidateCopilotToken

func ValidateCopilotToken(ctx context.Context, session CopilotSession) error

Types

type CopilotAPIToken added in v0.644.0

type CopilotAPIToken struct {
	Token         string
	ExpiresAt     int64
	APIEndpoint   string
	Organizations []string
	SKU           string
}

CopilotAPIToken is the result of exchanging a GitHub OAuth token for a short-lived Copilot API token.

func ExchangeCopilotAPIToken added in v0.644.0

func ExchangeCopilotAPIToken(ctx context.Context, oauthToken, enterpriseURL string) (*CopilotAPIToken, error)

ExchangeCopilotAPIToken trades a GitHub OAuth token for a short-lived Copilot API token. Results are cached in memory until shortly before expiry.

type CopilotAuthStatus

type CopilotAuthStatus struct {
	Authenticated bool
	Source        string
	EnterpriseURL string
	Message       string
}

func GetCopilotAuthStatus

func GetCopilotAuthStatus() CopilotAuthStatus

type CopilotDeviceCode

type CopilotDeviceCode struct {
	DeviceCode      string `json:"device_code"`
	UserCode        string `json:"user_code"`
	VerificationURI string `json:"verification_uri"`
	Interval        int    `json:"interval"`
	ExpiresIn       int    `json:"expires_in"`
}

func StartCopilotDeviceFlow

func StartCopilotDeviceFlow(ctx context.Context, enterpriseURL string) (*CopilotDeviceCode, error)

type CopilotSession

type CopilotSession struct {
	Provider      string `json:"provider,omitempty"`
	AccessToken   string `json:"access_token"`
	TokenType     string `json:"token_type,omitempty"`
	Scope         string `json:"scope,omitempty"`
	ExpiresAt     int64  `json:"expires_at,omitempty"`
	EnterpriseURL string `json:"enterprise_url,omitempty"`
	CreatedAt     int64  `json:"created_at,omitempty"`
}

func CompleteCopilotDeviceFlow

func CompleteCopilotDeviceFlow(ctx context.Context, enterpriseURL string, deviceCode *CopilotDeviceCode) (*CopilotSession, error)

func LoadCopilotSession

func LoadCopilotSession() (*CopilotSession, error)

func PollCopilotDeviceFlow

func PollCopilotDeviceFlow(ctx context.Context, enterpriseURL string, deviceCode *CopilotDeviceCode) (*CopilotSession, error)

type GitHubTokenCandidate added in v0.644.0

type GitHubTokenCandidate struct {
	Source string
	Token  string
}

GitHubTokenCandidate is a GitHub OAuth token discovered locally, tagged with where it came from.

func GitHubOAuthTokenCandidates added in v0.644.0

func GitHubOAuthTokenCandidates() []GitHubTokenCandidate

GitHubOAuthTokenCandidates returns every usable GitHub OAuth token found on this machine, in the same priority order LoadGitHubOAuthToken applies. Not all of them can be exchanged for a Copilot API token (only tokens issued to an app with Copilot entitlement can), so callers that need the exchanged token walk the list instead of taking just the first entry.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL