Fix false "Unauthorized" error when target repo name was renamed away - #1616
Merged
Merged
Conversation
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Disabling redirects on shared clients also affects GitLab and Bitbucket source requests.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Fixes false authorization failures caused by repository-name redirects.
Changes:
- Disables automatic redirects in
gl2ghandbbs2gh. - Corrects 301 handling test coverage.
- Adds release notes.
| File | Description |
|---|---|
src/gl2gh/Program.cs |
Configures HTTP redirect handling. |
src/bbs2gh/Program.cs |
Configures HTTP redirect handling. |
src/OctoshiftCLI.Tests/Octoshift/Services/GithubApiTests.cs |
Correctly exercises the 301 path. |
RELEASENOTES.md |
Documents the fix. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
iomekam
approved these changes
Oct 2, 2026
Unit Test Results 1 files 1 suites 24s ⏱️ Results for commit 6200325. ♻️ This comment has been updated with latest results. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Problem
Migrating to a target repo name that was previously used and renamed away (leaving a redirect) fails with a misleading
Unauthorized - check your tokenerror. The token is valid and the name is free — the migration should succeed.Cause
gl2ghandbbs2ghbuild their HTTP clients withAllowAutoRedirectleft at its default (true). The target-exists check hits a same-host 301, .NET follows it and strips theAuthorizationheader on the hop, and the anonymous retry returns a 401 that we rewrite into a token error.geialready setsAllowAutoRedirect = falseand is unaffected.Fix
AllowAutoRedirect = falseon thegl2ghandbbs2ghHTTP handlers, matchinggei. A 301 now surfaces toDoesRepoExistas "name is free" and the migration proceeds.DoesRepoExist_Returns_False_When_301, which previously asserted nothing (it stubbed the wrong status and never exercised the 301 path).Notes
ado2ghhas no target-exists probe, so it's unaffected and left as-is.Testing
Full unit suite passes (1176).
Did you write/update appropriate tests
Release notes updated (if appropriate)
Appropriate logging output
Issue linked
Docs updated (or issue created)
New package licenses are added to
ThirdPartyNotices.txt(if applicable)