fix(backend): fall back when GitHub App installation is missing - #1523

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails
Jul 31, 2026
Merged

fix(backend): fall back when GitHub App installation is missing#1523
brendan-kellam merged 2 commits into
mainfrom
brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1588

Summary

  • treat a missing GitHub App installation as an unavailable app credential instead of failing the entire connection sync
  • warn and fall back to the existing GitHub client when an owner has no matching installation
  • continue legacy repository credential resolution when no app installation token is available

Testing

  • yarn workspace @sourcebot/backend test --run src/ee/githubAppManager.test.ts src/githubAppAuth.test.ts
  • yarn workspace @sourcebot/backend build

Note

Medium Risk
Changes which credential path runs for GitHub API and git clone when apps are configured; wrong fallback could use weaker or insufficient PAT access for orgs without an installation.

Overview
Fixes GitHub connection syncs failing when the GitHub App is configured but not installed on every org in the connection.

GithubAppManager.getInstallationToken now returns undefined when there is no installation for an owner/host, instead of throwing. getOctokitWithGithubApp logs a warning and returns the existing (legacy PAT) Octokit when no installation token exists. getAuthCredentialsForRepo only uses the app installation token when one is available; otherwise it keeps walking connections for a legacy GitHub token.

Mixed setups—some orgs on the app, others only on PAT—can sync per-org without aborting the whole job.

Reviewed by Cursor Bugbot for commit b47a962. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes
    • GitHub connection synchronization now falls back to legacy authentication when the GitHub App is not installed for an organization.
    • Repository access continues using other available authentication methods when GitHub App credentials are unavailable.
    • Improved handling of GitHub App installations that cannot be found.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 4c52fb5d-8d7a-4f80-9dca-12043321c475

📥 Commits

Reviewing files that changed from the base of the PR and between 0a019d4 and b47a962.

📒 Files selected for processing (4)
  • CHANGELOG.md
  • packages/backend/src/ee/githubAppManager.ts
  • packages/backend/src/github.ts
  • packages/backend/src/utils.ts

Walkthrough

GitHub App authentication now treats missing installations as absent tokens. GitHub client creation falls back to legacy authentication, repository credential generation continues to other sources, and the changelog documents the Enterprise synchronization fix.

Changes

GitHub App authentication fallback

Layer / File(s)Summary
Represent missing installations as absent tokens
packages/backend/src/ee/githubAppManager.ts
getInstallationToken returns undefined instead of throwing when no matching installation exists.
Apply fallback behavior to authentication consumers
packages/backend/src/github.ts, packages/backend/src/utils.ts, CHANGELOG.md
GitHub client creation falls back to legacy authentication, repository credentials are skipped without an installation token, and the fix is documented.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers:msukkari

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@brendan-kellam
brendan-kellam merged commit b366d97 into mainJul 31, 2026
10 of 11 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails branch July 31, 2026 00:53
@github-actionsgithub-actionsBot mentioned this pull request Jul 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(backend): fall back when GitHub App installation is missing - #1523

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails
Jul 31, 2026
Merged

fix(backend): fall back when GitHub App installation is missing#1523
brendan-kellam merged 2 commits into
mainfrom
brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1588

Summary

  • treat a missing GitHub App installation as an unavailable app credential instead of failing the entire connection sync
  • warn and fall back to the existing GitHub client when an owner has no matching installation
  • continue legacy repository credential resolution when no app installation token is available

Testing

  • yarn workspace @sourcebot/backend test --run src/ee/githubAppManager.test.ts src/githubAppAuth.test.ts
  • yarn workspace @sourcebot/backend build

Note

Medium Risk
Changes which credential path runs for GitHub API and git clone when apps are configured; wrong fallback could use weaker or insufficient PAT access for orgs without an installation.

Overview
Fixes GitHub connection syncs failing when the GitHub App is configured but not installed on every org in the connection.

GithubAppManager.getInstallationToken now returns undefined when there is no installation for an owner/host, instead of throwing. getOctokitWithGithubApp logs a warning and returns the existing (legacy PAT) Octokit when no installation token exists. getAuthCredentialsForRepo only uses the app installation token when one is available; otherwise it keeps walking connections for a legacy GitHub token.

Mixed setups—some orgs on the app, others only on PAT—can sync per-org without aborting the whole job.

Reviewed by Cursor Bugbot for commit b47a962. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes
    • GitHub connection synchronization now falls back to legacy authentication when the GitHub App is not installed for an organization.
    • Repository access continues using other available authentication methods when GitHub App credentials are unavailable.
    • Improved handling of GitHub App installations that cannot be found.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 4c52fb5d-8d7a-4f80-9dca-12043321c475

📥 Commits

Reviewing files that changed from the base of the PR and between 0a019d4 and b47a962.

📒 Files selected for processing (4)
  • CHANGELOG.md
  • packages/backend/src/ee/githubAppManager.ts
  • packages/backend/src/github.ts
  • packages/backend/src/utils.ts

Walkthrough

GitHub App authentication now treats missing installations as absent tokens. GitHub client creation falls back to legacy authentication, repository credential generation continues to other sources, and the changelog documents the Enterprise synchronization fix.

Changes

GitHub App authentication fallback

Layer / File(s)Summary
Represent missing installations as absent tokens
packages/backend/src/ee/githubAppManager.ts
getInstallationToken returns undefined instead of throwing when no matching installation exists.
Apply fallback behavior to authentication consumers
packages/backend/src/github.ts, packages/backend/src/utils.ts, CHANGELOG.md
GitHub client creation falls back to legacy authentication, repository credentials are skipped without an installation token, and the fix is documented.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers:msukkari

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@brendan-kellam
brendan-kellam merged commit b366d97 into mainJul 31, 2026
10 of 11 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails branch July 31, 2026 00:53
@github-actionsgithub-actionsBot mentioned this pull request Jul 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(backend): fall back when GitHub App installation is missing - #1523

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails
Jul 31, 2026
Merged

fix(backend): fall back when GitHub App installation is missing#1523
brendan-kellam merged 2 commits into
mainfrom
brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1588

Summary

  • treat a missing GitHub App installation as an unavailable app credential instead of failing the entire connection sync
  • warn and fall back to the existing GitHub client when an owner has no matching installation
  • continue legacy repository credential resolution when no app installation token is available

Testing

  • yarn workspace @sourcebot/backend test --run src/ee/githubAppManager.test.ts src/githubAppAuth.test.ts
  • yarn workspace @sourcebot/backend build

Note

Medium Risk
Changes which credential path runs for GitHub API and git clone when apps are configured; wrong fallback could use weaker or insufficient PAT access for orgs without an installation.

Overview
Fixes GitHub connection syncs failing when the GitHub App is configured but not installed on every org in the connection.

GithubAppManager.getInstallationToken now returns undefined when there is no installation for an owner/host, instead of throwing. getOctokitWithGithubApp logs a warning and returns the existing (legacy PAT) Octokit when no installation token exists. getAuthCredentialsForRepo only uses the app installation token when one is available; otherwise it keeps walking connections for a legacy GitHub token.

Mixed setups—some orgs on the app, others only on PAT—can sync per-org without aborting the whole job.

Reviewed by Cursor Bugbot for commit b47a962. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes
    • GitHub connection synchronization now falls back to legacy authentication when the GitHub App is not installed for an organization.
    • Repository access continues using other available authentication methods when GitHub App credentials are unavailable.
    • Improved handling of GitHub App installations that cannot be found.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 4c52fb5d-8d7a-4f80-9dca-12043321c475

📥 Commits

Reviewing files that changed from the base of the PR and between 0a019d4 and b47a962.

📒 Files selected for processing (4)
  • CHANGELOG.md
  • packages/backend/src/ee/githubAppManager.ts
  • packages/backend/src/github.ts
  • packages/backend/src/utils.ts

Walkthrough

GitHub App authentication now treats missing installations as absent tokens. GitHub client creation falls back to legacy authentication, repository credential generation continues to other sources, and the changelog documents the Enterprise synchronization fix.

Changes

GitHub App authentication fallback

Layer / File(s)Summary
Represent missing installations as absent tokens
packages/backend/src/ee/githubAppManager.ts
getInstallationToken returns undefined instead of throwing when no matching installation exists.
Apply fallback behavior to authentication consumers
packages/backend/src/github.ts, packages/backend/src/utils.ts, CHANGELOG.md
GitHub client creation falls back to legacy authentication, repository credentials are skipped without an installation token, and the fix is documented.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers:msukkari

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@brendan-kellam
brendan-kellam merged commit b366d97 into mainJul 31, 2026
10 of 11 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails branch July 31, 2026 00:53
@github-actionsgithub-actionsBot mentioned this pull request Jul 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(backend): fall back when GitHub App installation is missing - #1523

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails
Jul 31, 2026
Merged

fix(backend): fall back when GitHub App installation is missing#1523
brendan-kellam merged 2 commits into
mainfrom
brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1588

Summary

  • treat a missing GitHub App installation as an unavailable app credential instead of failing the entire connection sync
  • warn and fall back to the existing GitHub client when an owner has no matching installation
  • continue legacy repository credential resolution when no app installation token is available

Testing

  • yarn workspace @sourcebot/backend test --run src/ee/githubAppManager.test.ts src/githubAppAuth.test.ts
  • yarn workspace @sourcebot/backend build

Note

Medium Risk
Changes which credential path runs for GitHub API and git clone when apps are configured; wrong fallback could use weaker or insufficient PAT access for orgs without an installation.

Overview
Fixes GitHub connection syncs failing when the GitHub App is configured but not installed on every org in the connection.

GithubAppManager.getInstallationToken now returns undefined when there is no installation for an owner/host, instead of throwing. getOctokitWithGithubApp logs a warning and returns the existing (legacy PAT) Octokit when no installation token exists. getAuthCredentialsForRepo only uses the app installation token when one is available; otherwise it keeps walking connections for a legacy GitHub token.

Mixed setups—some orgs on the app, others only on PAT—can sync per-org without aborting the whole job.

Reviewed by Cursor Bugbot for commit b47a962. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes
    • GitHub connection synchronization now falls back to legacy authentication when the GitHub App is not installed for an organization.
    • Repository access continues using other available authentication methods when GitHub App credentials are unavailable.
    • Improved handling of GitHub App installations that cannot be found.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 4c52fb5d-8d7a-4f80-9dca-12043321c475

📥 Commits

Reviewing files that changed from the base of the PR and between 0a019d4 and b47a962.

📒 Files selected for processing (4)
  • CHANGELOG.md
  • packages/backend/src/ee/githubAppManager.ts
  • packages/backend/src/github.ts
  • packages/backend/src/utils.ts

Walkthrough

GitHub App authentication now treats missing installations as absent tokens. GitHub client creation falls back to legacy authentication, repository credential generation continues to other sources, and the changelog documents the Enterprise synchronization fix.

Changes

GitHub App authentication fallback

Layer / File(s)Summary
Represent missing installations as absent tokens
packages/backend/src/ee/githubAppManager.ts
getInstallationToken returns undefined instead of throwing when no matching installation exists.
Apply fallback behavior to authentication consumers
packages/backend/src/github.ts, packages/backend/src/utils.ts, CHANGELOG.md
GitHub client creation falls back to legacy authentication, repository credentials are skipped without an installation token, and the fix is documented.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers:msukkari

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@brendan-kellam
brendan-kellam merged commit b366d97 into mainJul 31, 2026
10 of 11 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails branch July 31, 2026 00:53
@github-actionsgithub-actionsBot mentioned this pull request Jul 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(backend): fall back when GitHub App installation is missing - #1523

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails
Jul 31, 2026
Merged

fix(backend): fall back when GitHub App installation is missing#1523
brendan-kellam merged 2 commits into
mainfrom
brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1588

Summary

  • treat a missing GitHub App installation as an unavailable app credential instead of failing the entire connection sync
  • warn and fall back to the existing GitHub client when an owner has no matching installation
  • continue legacy repository credential resolution when no app installation token is available

Testing

  • yarn workspace @sourcebot/backend test --run src/ee/githubAppManager.test.ts src/githubAppAuth.test.ts
  • yarn workspace @sourcebot/backend build

Note

Medium Risk
Changes which credential path runs for GitHub API and git clone when apps are configured; wrong fallback could use weaker or insufficient PAT access for orgs without an installation.

Overview
Fixes GitHub connection syncs failing when the GitHub App is configured but not installed on every org in the connection.

GithubAppManager.getInstallationToken now returns undefined when there is no installation for an owner/host, instead of throwing. getOctokitWithGithubApp logs a warning and returns the existing (legacy PAT) Octokit when no installation token exists. getAuthCredentialsForRepo only uses the app installation token when one is available; otherwise it keeps walking connections for a legacy GitHub token.

Mixed setups—some orgs on the app, others only on PAT—can sync per-org without aborting the whole job.

Reviewed by Cursor Bugbot for commit b47a962. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes
    • GitHub connection synchronization now falls back to legacy authentication when the GitHub App is not installed for an organization.
    • Repository access continues using other available authentication methods when GitHub App credentials are unavailable.
    • Improved handling of GitHub App installations that cannot be found.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 4c52fb5d-8d7a-4f80-9dca-12043321c475

📥 Commits

Reviewing files that changed from the base of the PR and between 0a019d4 and b47a962.

📒 Files selected for processing (4)
  • CHANGELOG.md
  • packages/backend/src/ee/githubAppManager.ts
  • packages/backend/src/github.ts
  • packages/backend/src/utils.ts

Walkthrough

GitHub App authentication now treats missing installations as absent tokens. GitHub client creation falls back to legacy authentication, repository credential generation continues to other sources, and the changelog documents the Enterprise synchronization fix.

Changes

GitHub App authentication fallback

Layer / File(s)Summary
Represent missing installations as absent tokens
packages/backend/src/ee/githubAppManager.ts
getInstallationToken returns undefined instead of throwing when no matching installation exists.
Apply fallback behavior to authentication consumers
packages/backend/src/github.ts, packages/backend/src/utils.ts, CHANGELOG.md
GitHub client creation falls back to legacy authentication, repository credentials are skipped without an installation token, and the fix is documented.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers:msukkari

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@brendan-kellam
brendan-kellam merged commit b366d97 into mainJul 31, 2026
10 of 11 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails branch July 31, 2026 00:53
@github-actionsgithub-actionsBot mentioned this pull request Jul 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(backend): fall back when GitHub App installation is missing - #1523

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails
Jul 31, 2026
Merged

fix(backend): fall back when GitHub App installation is missing#1523
brendan-kellam merged 2 commits into
mainfrom
brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1588

Summary

  • treat a missing GitHub App installation as an unavailable app credential instead of failing the entire connection sync
  • warn and fall back to the existing GitHub client when an owner has no matching installation
  • continue legacy repository credential resolution when no app installation token is available

Testing

  • yarn workspace @sourcebot/backend test --run src/ee/githubAppManager.test.ts src/githubAppAuth.test.ts
  • yarn workspace @sourcebot/backend build

Note

Medium Risk
Changes which credential path runs for GitHub API and git clone when apps are configured; wrong fallback could use weaker or insufficient PAT access for orgs without an installation.

Overview
Fixes GitHub connection syncs failing when the GitHub App is configured but not installed on every org in the connection.

GithubAppManager.getInstallationToken now returns undefined when there is no installation for an owner/host, instead of throwing. getOctokitWithGithubApp logs a warning and returns the existing (legacy PAT) Octokit when no installation token exists. getAuthCredentialsForRepo only uses the app installation token when one is available; otherwise it keeps walking connections for a legacy GitHub token.

Mixed setups—some orgs on the app, others only on PAT—can sync per-org without aborting the whole job.

Reviewed by Cursor Bugbot for commit b47a962. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes
    • GitHub connection synchronization now falls back to legacy authentication when the GitHub App is not installed for an organization.
    • Repository access continues using other available authentication methods when GitHub App credentials are unavailable.
    • Improved handling of GitHub App installations that cannot be found.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 4c52fb5d-8d7a-4f80-9dca-12043321c475

📥 Commits

Reviewing files that changed from the base of the PR and between 0a019d4 and b47a962.

📒 Files selected for processing (4)
  • CHANGELOG.md
  • packages/backend/src/ee/githubAppManager.ts
  • packages/backend/src/github.ts
  • packages/backend/src/utils.ts

Walkthrough

GitHub App authentication now treats missing installations as absent tokens. GitHub client creation falls back to legacy authentication, repository credential generation continues to other sources, and the changelog documents the Enterprise synchronization fix.

Changes

GitHub App authentication fallback

Layer / File(s)Summary
Represent missing installations as absent tokens
packages/backend/src/ee/githubAppManager.ts
getInstallationToken returns undefined instead of throwing when no matching installation exists.
Apply fallback behavior to authentication consumers
packages/backend/src/github.ts, packages/backend/src/utils.ts, CHANGELOG.md
GitHub client creation falls back to legacy authentication, repository credentials are skipped without an installation token, and the fix is documented.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers:msukkari

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@brendan-kellam
brendan-kellam merged commit b366d97 into mainJul 31, 2026
10 of 11 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails branch July 31, 2026 00:53
@github-actionsgithub-actionsBot mentioned this pull request Jul 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(backend): fall back when GitHub App installation is missing - #1523

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails
Jul 31, 2026
Merged

fix(backend): fall back when GitHub App installation is missing#1523
brendan-kellam merged 2 commits into
mainfrom
brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1588

Summary

  • treat a missing GitHub App installation as an unavailable app credential instead of failing the entire connection sync
  • warn and fall back to the existing GitHub client when an owner has no matching installation
  • continue legacy repository credential resolution when no app installation token is available

Testing

  • yarn workspace @sourcebot/backend test --run src/ee/githubAppManager.test.ts src/githubAppAuth.test.ts
  • yarn workspace @sourcebot/backend build

Note

Medium Risk
Changes which credential path runs for GitHub API and git clone when apps are configured; wrong fallback could use weaker or insufficient PAT access for orgs without an installation.

Overview
Fixes GitHub connection syncs failing when the GitHub App is configured but not installed on every org in the connection.

GithubAppManager.getInstallationToken now returns undefined when there is no installation for an owner/host, instead of throwing. getOctokitWithGithubApp logs a warning and returns the existing (legacy PAT) Octokit when no installation token exists. getAuthCredentialsForRepo only uses the app installation token when one is available; otherwise it keeps walking connections for a legacy GitHub token.

Mixed setups—some orgs on the app, others only on PAT—can sync per-org without aborting the whole job.

Reviewed by Cursor Bugbot for commit b47a962. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes
    • GitHub connection synchronization now falls back to legacy authentication when the GitHub App is not installed for an organization.
    • Repository access continues using other available authentication methods when GitHub App credentials are unavailable.
    • Improved handling of GitHub App installations that cannot be found.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 4c52fb5d-8d7a-4f80-9dca-12043321c475

📥 Commits

Reviewing files that changed from the base of the PR and between 0a019d4 and b47a962.

📒 Files selected for processing (4)
  • CHANGELOG.md
  • packages/backend/src/ee/githubAppManager.ts
  • packages/backend/src/github.ts
  • packages/backend/src/utils.ts

Walkthrough

GitHub App authentication now treats missing installations as absent tokens. GitHub client creation falls back to legacy authentication, repository credential generation continues to other sources, and the changelog documents the Enterprise synchronization fix.

Changes

GitHub App authentication fallback

Layer / File(s)Summary
Represent missing installations as absent tokens
packages/backend/src/ee/githubAppManager.ts
getInstallationToken returns undefined instead of throwing when no matching installation exists.
Apply fallback behavior to authentication consumers
packages/backend/src/github.ts, packages/backend/src/utils.ts, CHANGELOG.md
GitHub client creation falls back to legacy authentication, repository credentials are skipped without an installation token, and the fix is documented.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers:msukkari

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@brendan-kellam
brendan-kellam merged commit b366d97 into mainJul 31, 2026
10 of 11 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails branch July 31, 2026 00:53
@github-actionsgithub-actionsBot mentioned this pull request Jul 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(backend): fall back when GitHub App installation is missing - #1523

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails
Jul 31, 2026
Merged

fix(backend): fall back when GitHub App installation is missing#1523
brendan-kellam merged 2 commits into
mainfrom
brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1588

Summary

  • treat a missing GitHub App installation as an unavailable app credential instead of failing the entire connection sync
  • warn and fall back to the existing GitHub client when an owner has no matching installation
  • continue legacy repository credential resolution when no app installation token is available

Testing

  • yarn workspace @sourcebot/backend test --run src/ee/githubAppManager.test.ts src/githubAppAuth.test.ts
  • yarn workspace @sourcebot/backend build

Note

Medium Risk
Changes which credential path runs for GitHub API and git clone when apps are configured; wrong fallback could use weaker or insufficient PAT access for orgs without an installation.

Overview
Fixes GitHub connection syncs failing when the GitHub App is configured but not installed on every org in the connection.

GithubAppManager.getInstallationToken now returns undefined when there is no installation for an owner/host, instead of throwing. getOctokitWithGithubApp logs a warning and returns the existing (legacy PAT) Octokit when no installation token exists. getAuthCredentialsForRepo only uses the app installation token when one is available; otherwise it keeps walking connections for a legacy GitHub token.

Mixed setups—some orgs on the app, others only on PAT—can sync per-org without aborting the whole job.

Reviewed by Cursor Bugbot for commit b47a962. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes
    • GitHub connection synchronization now falls back to legacy authentication when the GitHub App is not installed for an organization.
    • Repository access continues using other available authentication methods when GitHub App credentials are unavailable.
    • Improved handling of GitHub App installations that cannot be found.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 4c52fb5d-8d7a-4f80-9dca-12043321c475

📥 Commits

Reviewing files that changed from the base of the PR and between 0a019d4 and b47a962.

📒 Files selected for processing (4)
  • CHANGELOG.md
  • packages/backend/src/ee/githubAppManager.ts
  • packages/backend/src/github.ts
  • packages/backend/src/utils.ts

Walkthrough

GitHub App authentication now treats missing installations as absent tokens. GitHub client creation falls back to legacy authentication, repository credential generation continues to other sources, and the changelog documents the Enterprise synchronization fix.

Changes

GitHub App authentication fallback

Layer / File(s)Summary
Represent missing installations as absent tokens
packages/backend/src/ee/githubAppManager.ts
getInstallationToken returns undefined instead of throwing when no matching installation exists.
Apply fallback behavior to authentication consumers
packages/backend/src/github.ts, packages/backend/src/utils.ts, CHANGELOG.md
GitHub client creation falls back to legacy authentication, repository credentials are skipped without an installation token, and the fix is documented.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers:msukkari

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@brendan-kellam
brendan-kellam merged commit b366d97 into mainJul 31, 2026
10 of 11 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/sou-1588-connection-sync-fails-when-one-org-sync-fails branch July 31, 2026 00:53
@github-actionsgithub-actionsBot mentioned this pull request Jul 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam