mirror of
https://github.com/Tencent/teamai-cli.git
synced 2026-10-02 03:14:40 +08:00
* feat(gitcode): add GitCode (gitcode.com) provider support
Add a Gitee-style v5 REST provider for gitcode.com (issue #361):
- src/providers/gitcode/ implementing GitProvider (parse/auth/clone/
createRepo/createPullRequest/fetchMR/listOrgRepos)
- Register gitcode in HOST_MAP/KNOWN_PROVIDERS/PROVIDERS + types enum
- doctor + clone (shallowClone) gitcode branches
- Team-repo clone embeds oauth2:<token>@ in the remote URL so the
branch+PR push flow authenticates (GitCode git endpoint rejects Bearer)
- Interactive PAT paste on init, persisted to ~/.netrc
- Unit tests + opt-in live e2e
* docs(gitcode): document GitCode provider across guides + design doc
- providers.md: provider table (6), detection block, GitCode section
- README + README.zh-CN: add GitCode to provider list
- usage-guide + zh-CN: add GitCode to repo-host list
- docs/designs/gitcode-provider.md: design + verified dialect + push-auth fix
* fix(gitcode): handle ssh:// URLs with port + persist clone creds for fetch
Address PR #376 review:
- parseGitCodeRepoInput now strips a leading ssh://[user@]host[:port]/ prefix,
so `ssh://git@gitcode.com:2222/owner/repo.git` parses to owner/repo instead
of owner=ssh:. Adds unit tests for the port and no-port forms.
- shallowClone (import cache) embeds oauth2:<token>@ in the clone URL instead of
a one-shot http.extraHeader, so the origin remote persists credentials and the
twin shallowFetch()'s plain `git fetch` authenticates on private repos without
a credential helper. Mirrors the tgit branch; token is redacted in errors via
sanitizeGitUrl. Verified live with credential.helper disabled.
* fix(gitcode): inject fetch auth via extraHeader, not URL-embedded token
Address automated security review of 6582e3c: embedding oauth2:<token>@ in the
import-cache clone URL persisted the token into that repo's .git/config
(secret at rest). Revert shallowClone to the non-persisted http.extraHeader,
and give shallowFetch a matching per-invocation extraHeader (new fetchAuthHeader
covers github/gitlab/gitcode) so private-repo incremental fetch still
authenticates without a credential helper — verified live with credential.helper
disabled: fetch succeeds and .git/config contains no token.
The team-repo clone (providers/gitcode/gitcode-api.ts) still embeds the token,
matching github/tgit: its push flow uses a plain git push with no per-command
header, so persisted creds are required there.