Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
Show all changes
38 commits
Select commit Hold shift + click to select a range
c219743
Add acceptance coverage for gist
williammartin Aug 7, 2026
bceaa3b
Wait longer for the search index in the issues script
williammartin Aug 7, 2026
0f3ab22
Let GH_ACCEPTANCE_SCRIPT name several scripts
williammartin Aug 7, 2026
eae00d0
Add the api_host gateway harness
williammartin Aug 7, 2026
3189464
Send a host's token to its configured api_host
williammartin Aug 7, 2026
2d89b26
Make gh api honour api_host for relative paths
williammartin Aug 7, 2026
670b2a3
Send RenameRepo to a relative path
williammartin Aug 7, 2026
62a6e9e
Add a raw response request surface to api.Client
williammartin Aug 7, 2026
216199e
Let a caller name the scopes an endpoint needs
williammartin Aug 7, 2026
eae1deb
Let a caller stop a request following redirects
williammartin Aug 7, 2026
6fcf2ea
Let callers set headers on a shared client request
williammartin Aug 7, 2026
ffb187b
Send release asset uploads and downloads through api.Client
williammartin Aug 7, 2026
97fcb73
docs(api): clarify redirect method-rewriting in comments
babakks Aug 27, 2026
dbbaed8
fix(config): resolve api_host collisions deterministically
babakks Aug 27, 2026
fbda842
refactor(api): use errors.AsType for HTTP error checks
babakks Aug 27, 2026
d5ff05b
test(acceptance): cover selecting multiple scripts in one directory
babakks Aug 27, 2026
c67d0e6
test(api): assert DoRequest preserves an explicit ContentLength
babakks Aug 27, 2026
2266020
test(config): cover deterministic api_host collision resolution
babakks Aug 27, 2026
62f5a7c
test(config): add coverage for APIHostForHost
babakks Aug 27, 2026
061b2a1
fix(auth/shared): route GetScopes path through safeurl
babakks Aug 27, 2026
fcd05d9
chore(codeql): cover api.Client.Request in SafeURL path query
babakks Aug 27, 2026
4288f57
build(deps): bump go-gh to per-host api_host branch
babakks Aug 27, 2026
95107ff
test(acceptance): fix scriptfilter table field alignment
babakks Aug 27, 2026
48922ac
fix(api): compare request hostname without port when attaching auth t…
babakks Aug 28, 2026
ee5ed71
chore: tidy go.sum
babakks Aug 28, 2026
e7675c9
test(internal/attachments): add new method required by interface
babakks Aug 28, 2026
061e585
chore: apply go fix
babakks Aug 28, 2026
2f88d05
refactor(attachments): send uploads through api.Client.DoRequest
babakks Aug 28, 2026
6656e47
build(deps): bump go-gh to rebased per-host api_host branch
babakks Aug 28, 2026
fe76ff5
Rename tokenGetter to config
williammartin Sep 2, 2026
628e85c
Refactor AddAuthTokenHeader
williammartin Sep 2, 2026
714e5ea
Document when telemetry disabling is overzealous
williammartin Sep 2, 2026
8b3e2f1
Comment missing api-client-rollout todo
williammartin Sep 2, 2026
5ba76c6
Comment api command api_host usage
williammartin Sep 2, 2026
6e7b1fe
Remove redundant comment in gist create
williammartin Sep 2, 2026
0580da9
Remove unnecessary 204 on release edit
williammartin Sep 2, 2026
05a0a02
Remove redundant searcher comment
williammartin Sep 2, 2026
6865464
Bump go-gh to v2.15.0
williammartin Sep 2, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
docs(api): clarify redirect method-rewriting in comments
Note that Go's default redirect policy rewrites any non-GET/HEAD method
(not just DELETE) to GET on 301/302/303, and document why repo delete
opts out of following redirects to avoid a phantom success.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb7763a9-2086-461a-91a4-86ea4a2d078d
  • Loading branch information
2 people authored and williammartin committed Sep 2, 2026
commit 97fcb734c46313f952e205ea0f93e011cd28e59e
6 changes: 3 additions & 3 deletions api/client.go
Original file line number Diff line number Diff line change
Expand Up @@ -73,9 +73,9 @@ func WithHeader(name, value string) RequestOption {
// WithoutFollowingRedirects stops the request from following redirects. When a redirect is
// encountered, the request fails with an HTTPError carrying the redirect status code and headers
// rather than following the redirect. This matters for requests where following a redirect
// silently changes the meaning of the request: Go's default policy converts a DELETE into a GET
// when it follows a 301, so a caller deleting a renamed resource would receive a success response
// while having deleted nothing.
// silently changes the meaning of the request: Go's default policy converts methods other than
// GET or HEAD (e.g. DELETE) into a GET when it follows a 301/302/303, so a caller deleting a renamed
// resource would receive a success response while having deleted nothing.
//
// This option applies only to the REST request surface (Request and RequestWithContext). It has no
// effect on GraphQL methods, which do not encounter redirects in practice.
Expand Down
4 changes: 2 additions & 2 deletions api/client_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -355,8 +355,8 @@ func TestHTTPHeaders(t *testing.T) {
// TestWithoutFollowingRedirects verifies that WithoutFollowingRedirects stops the request at the
// redirect and surfaces an HTTPError rather than following through. It also proves the redirect is
// not followed by recording every method the transport sees: without the option the transport would
// receive a second call (GET, because Go demotes DELETE to GET on a 301 follow); with it, only the
// original DELETE arrives.
// receive a second call (GET, because Go demotes non-GET/HEAD to GET on a 301/302/303
// follow); with it, only the original DELETE arrives.
//
// go-gh's RequestWithContext converts any non-2xx response - including 3xx - into an HTTPError.
// When http.ErrUseLastResponse stops a redirect the client returns the 3xx response with a nil
Expand Down
6 changes: 6 additions & 0 deletions pkg/cmd/repo/delete/http.go
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,12 @@ func deleteRepo(httpClient *http.Client, repo ghrepo.Interface) error {
return err
}

// If the repo is renamed (and we're using the old name), the API will return
// an HTTP 307 (temporary redirect), which is a METHOD-preserving redirection.
// That is, upon receiving a 307, the HTTP client will repeat the same HTTP
// method (in this case, DELETE) but against the new location. We don't want
// such an implicit behaviour, so we pass the `api.WithoutFollowingRedirects`
// to make sure an error is returned.
resp, err := api.NewClientFromHTTP(httpClient).Request(repo.RepoHost(), http.MethodDelete, p.String(), nil,
api.WithEndpointScopes("delete_repo"),
api.WithoutFollowingRedirects(),
Expand Down