Skip to content

fix(credentials): keep the field-less GitHub App installation out of v2 provider discovery - #8632

Merged
TheodoreSpeaks merged 1 commit into
stagingfrom
fix/claude-session
Oct 5, 2026
Merged

TheodoreSpeaks merged 1 commit into
stagingfrom
fix/claude-session

Conversation

@TheodoreSpeaks

Copy link
Copy Markdown
Collaborator

Summary

  • GET /api/v2/credentials/providers 500'd on every unfiltered call: the GitHub App installation is listed as a service_account provider with fields: [], and the v2 contract requires at least one create field, so response validation threw
  • This broke sim credentials create <service-account provider> for every provider (the CLI preflights against the unfiltered catalog), plus the unfiltered providers listing
  • GitHub App installations are connected through Search integrations and credential creation always rejects them, so the v2 listing now omits that provider; the internal catalog keeps it for existing-credential access checks
  • Contract unchanged: any other service-account provider advertising no create fields still fails loudly

Type of Change

  • Bug fix

Testing

  • New provider-catalog-contract.test.ts runs the real catalog through the use case + v2 response contract: full catalog validates, internal catalog still carries the installation, filtered Claude Platform listing, policy-disabled provider stays listed as available: false. Full-catalog and policy cases fail on the pre-fix code
  • sim-cli credentials.test.ts: Claude Platform create preflights the unfiltered catalog and sends the expected create body; policy-disabled provider refused before create
  • bun run --cwd apps/sim test lib/credentials app/api/v2/credentials (518 passed), bun run lint, bun run check:audits, bun run docs-manifest:check, block-registry check, root bun run test (only failures are 3 env-dependent rate-limit/timeout tests reading a local .env, untouched here)

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

🤖 Generated with Claude Code

https://claude.ai/code/session_01B6NMzbxwntSGJe4b32vjCz

@vercel

vercel Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 5, 2026 7:55pm UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 3 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@greptile-apps

greptile-apps Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Medium risk] Filters GitHub App installation from credential provider discovery.

The PR appears safe to merge; no actionable regressions were identified.

Summary

The PR removes the field-less GitHub App installation from v2 credential-provider discovery while retaining it in the internal catalog. New tests check response-contract validation, filtered discovery, policy-disabled providers, and CLI creation preflight.

Reviews (1) · Last reviewed commit: "fix(credentials): keep the field-less Gi..."

@TheodoreSpeaks
TheodoreSpeaks merged commit 6b3cd82 into staging Oct 5, 2026
33 checks passed
@TheodoreSpeaks
TheodoreSpeaks deleted the fix/claude-session branch October 5, 2026 21:49

This branch was previously deployed

1 inactive deployment
Preview — e8a218d8 Deployed Oct 5, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant