fix: renew public grants and verify source identity and visibility

This commit is contained in:
Thomas Durieux committed 2026-09-13 15:05:43 +00:00
1 parent 8efb9bd506
commit 5e5cc6e0c2
6 files changed
+79 -27

No files matched your search

+1 -1
View File
@@ -495,7 +495,7 @@ router.post(
}
if (repoUpdate.fullName !== repo.model.source.repositoryName && user.id !== repo.owner.id) throw appError("not_owner", 403);
const sourceAccess = repo.model.githubAccess?.kind === "github-app" && repoUpdate.fullName === repo.model.source.repositoryName
? { token: await boundAppToken(repo.owner.id, repo.model.githubAccess), binding: repo.model.githubAccess }
? { token: await boundAppToken(repo.owner.id, repo.model.githubAccess, repo.model.source.repositoryName), binding: repo.model.githubAccess }
: await selectRepositoryAccess(repo.owner.id, `${parsedRepository.owner}/${parsedRepository.name}`, repo.model.githubAccess?.kind || "oauth");
const repository = await getRepositoryFromGitHub({
accessToken: sourceAccess.token,