Use Bearer authentication to support fine-grained GitLab PATs - #381
Merged
Merged
Conversation
This was referenced Sep 16, 2026
mglaman
added a commit
that referenced
this pull request
Sep 22, 2026
* test: assert on the requests the GitLab client sends Both HTTP clients accept an optional HandlerStack. When one is passed it still gets the retry middleware, the default headers, and the base_uri, so a test can build the stack around a MockHandler plus Guzzle's history middleware and inspect what was actually sent. The new GitLab client test covers the gap #381 exposed: the Bearer header, the User-Agent and Accept headers, the unauthenticated case, project path encoding, note pagination, the concurrent getIssuesByIid() fan-out, the JSON body of a slash command note, and a 503 recovered by the retry middleware. Refs #382 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * test: assert on the requests the Drupal.org client sends Replace the anonymous subclass that swapped in a bare Guzzle client with the HandlerStack the constructor now accepts. The client under test keeps its headers, base_uri, cookie jar, and retry middleware, so the test can cover the default headers, the --no-cache headers, cookie persistence across requests, the request URLs, and a 503 recovered by the retry middleware. Refs #382 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * fix: fail with an exception when no git repository is found initRepo() called exit(1) from inside the command, which no test can observe. It also never reached that branch: when git rev-parse fails its output is empty, and realpath('') is the current directory, so GitRepository opened a non-repository without complaint and the failure surfaced later as an unrelated GitException. Check the git process result and throw a RuntimeException. The console application renders the message and exits 1, so the user-facing exit code is unchanged. Refs #382 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * test: run IssueCommandBase::initialize() against a temporary git repository Each test runs a throwaway command inside a fresh temporary directory, with or without a git repository in it, and asserts on the nid, the work item reference, and whether the repository was opened. This covers the regression fixed in #385, where a project#nid or work item URL argument returned before initRepo() ran, along with reading the nid from the branch name and both failure messages. Refs #382 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Send GitLab API tokens using
Authorization: Bearerinstead ofPRIVATE-TOKENto support fine-grained PATs. GitLab also supports Bearer authentication for classic PATs, so no separate mode is needed.Token resolution is unchanged:
DRUPALORG_GITLAB_TOKENtakes precedence over the existingglabfallback.Testing
With both classic and fine-grained PATs:
Verify note creation separately from bot-applied changes, which may be delayed.