fxgagnon opened a new pull request, #8850:
URL: https://github.com/apache/incubator-devlake/pull/8850

   GitHub App installation tokens expire after ~1 hour, causing admin APIs 
(remote-scopes, test-connection) to fail silently after token expiry.
   
   This fix overrides GetHash() to return empty string for GitHub App 
connections, disabling client caching and ensuring fresh tokens are fetched for 
each admin request.
   
   PAT connections continue to use default caching behavior.
   
   Fixes #8847
   
   <!--
   Licensed to the Apache Software Foundation (ASF) under one or more
   contributor license agreements.  See the NOTICE file distributed with
   this work for additional information regarding copyright ownership.
   The ASF licenses this file to You under the Apache License, Version 2.0
   (the "License"); you may not use this file except in compliance with
   the License.  You may obtain a copy of the License at
   
       http://www.apache.org/licenses/LICENSE-2.0
   
   Unless required by applicable law or agreed to in writing, software
   distributed under the License is distributed on an "AS IS" BASIS,
   WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
   See the License for the specific language governing permissions and
   limitations under the License.
   -->
   ### ⚠️ Pre Checklist
   
   > Please complete _ALL_ items in this checklist, and remove before submitting
   
   - [x] I have read through the [Contributing 
Documentation](https://devlake.apache.org/community/).
   - [x] I have added relevant tests.
   - [x] I have added relevant documentation.
   - [x] I will add labels to the PR, such as `pr-type/bug-fix`, 
`pr-type/feature-development`, etc.
   
   <!--
   Thanks for submitting a pull request!
   
   We appreciate you spending the time to work on these changes.
   Please fill out as many sections below as possible.
   -->
   
   ## Summary
   Fixes GitHub App installation token expiration issue causing admin APIs to 
fail silently after 1 hour.
   
   ## Problem
   GitHub App connections use installation tokens that expire after ~1 hour. 
Admin APIs (remote-scopes, test-connection) were reusing cached HTTP clients 
with expired tokens, causing silent failures.
   
   ## Root Cause
   `DsRemoteApiProxyHelper.getApiClient()` caches HTTP clients using 
`connection.GetHash()`. Once cached, clients are reused indefinitely with their 
embedded tokens.
   
   ## Solution
   Override `GetHash()` method in `GithubConnection` to return empty string for 
GitHub App connections, disabling client caching and ensuring fresh tokens are 
fetched for each admin request.
   
   Follows the same pattern as Zentao plugin for connections with expiring 
credentials.
   
   ## Changes
   - `backend/plugins/github/models/connection.go`: Added `GetHash()` method
   - `backend/plugins/github/models/connection_test.go`: Added test for 
`GetHash()` logic
   
   ## Testing
   - Unit tests pass for both GitHub App and PAT connections
   - No impact on data collection (uses separate client creation path)
   
   Fixes #8847


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to