jeff3071 commented on code in PR #73662:
URL: https://github.com/apache/airflow/pull/73662#discussion_r4101565434
##########
providers/git/src/airflow/providers/git/hooks/git.py:
##########
@@ -154,20 +161,36 @@ def __init__(
if all(github_app_fields):
if self.auth_token:
raise ValueError("Password field must be empty to use GitHub
App Auth")
- if not (self.repo_url or "").startswith(("https://", "http://")):
+ repo_url = self.repo_url or ""
+ if not repo_url.startswith(("https://", "http://")):
raise ValueError(
f"GitHub App authentication requires an HTTPS repository
URL, but got: {self.repo_url!r}"
)
+ self.github_api_url = extra.get("github_api_url")
+ if not self.github_api_url:
+ repo_host = urlsplit(repo_url).hostname or ""
+ if repo_host != "github.com":
+ raise ValueError(
+ f"GitHub App authentication against {repo_host!r}
requires 'github_api_url' "
+ "in the connection extra. The default API URL only
serves repositories "
+ "on 'github.com'."
+ )
+ self.github_api_url = _DEFAULT_GITHUB_API_URL
if self.key_file and not self.private_key:
with open(self.key_file, encoding="utf-8") as key_file:
self.private_key = key_file.read()
_VALID_STRICT_HOST_KEY_CHECKING = frozenset({"yes", "no", "accept-new",
"off", "ask"})
_SSH_REPO_URL_PATTERN = re.compile(r"^[^/@:]+@[^/:]+:")
+ def _uses_github_app_auth(self) -> bool:
+ return bool(self.github_app_id and self.github_installation_id)
+
def _uses_ssh_transport_options(self) -> bool:
# Heuristic: any SSH-specific option implies SSH; otherwise fall back
to the URL scheme.
# A bare ssh-config Host alias (no ``user@``) without SSH options is
not detected.
+ if self._uses_github_app_auth():
+ return False
Review Comment:
Adding this early return changes how `key_file` and `private_key` are
interpreted when GitHub App fields are present.
When both `github_app_id` and `github_installation_id` are configured, these
key fields are treated as the GitHub App signing key rather than as SSH
transport options. The hook therefore no longer emits the SSH host-key warning.
But `test_github_app_token_is_scoped_to_the_repository_host` still expects that
warning, so it now fails with `DID NOT WARN`.
For example:
```
{
"host": "https://github.example.com/org/repo.git",
"extra": {
"github_app_id": "12345",
"github_installation_id": "67890",
"private_key": "<GitHub App PEM>",
"github_api_url": "https://github.example.com/api/v3"
}
}
```
Here, `private_key` is not used as an SSH key. It signs the App JWT,
`github_api_url` mints the installation token, and that token authenticates Git
operations against `host`.
It would also be helpful to document the precedence when those field
configured .
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]