Files
teamai-cli/docs
jeff 0ebc724b8b feat(gitcode): add GitCode (gitcode.com) provider support (#361) (#376)
* feat(gitcode): add GitCode (gitcode.com) provider support

Add a Gitee-style v5 REST provider for gitcode.com (issue #361):
- src/providers/gitcode/ implementing GitProvider (parse/auth/clone/
  createRepo/createPullRequest/fetchMR/listOrgRepos)
- Register gitcode in HOST_MAP/KNOWN_PROVIDERS/PROVIDERS + types enum
- doctor + clone (shallowClone) gitcode branches
- Team-repo clone embeds oauth2:<token>@ in the remote URL so the
  branch+PR push flow authenticates (GitCode git endpoint rejects Bearer)
- Interactive PAT paste on init, persisted to ~/.netrc
- Unit tests + opt-in live e2e

* docs(gitcode): document GitCode provider across guides + design doc

- providers.md: provider table (6), detection block, GitCode section
- README + README.zh-CN: add GitCode to provider list
- usage-guide + zh-CN: add GitCode to repo-host list
- docs/designs/gitcode-provider.md: design + verified dialect + push-auth fix

* fix(gitcode): handle ssh:// URLs with port + persist clone creds for fetch

Address PR #376 review:
- parseGitCodeRepoInput now strips a leading ssh://[user@]host[:port]/ prefix,
  so `ssh://git@gitcode.com:2222/owner/repo.git` parses to owner/repo instead
  of owner=ssh:. Adds unit tests for the port and no-port forms.
- shallowClone (import cache) embeds oauth2:<token>@ in the clone URL instead of
  a one-shot http.extraHeader, so the origin remote persists credentials and the
  twin shallowFetch()'s plain `git fetch` authenticates on private repos without
  a credential helper. Mirrors the tgit branch; token is redacted in errors via
  sanitizeGitUrl. Verified live with credential.helper disabled.

* fix(gitcode): inject fetch auth via extraHeader, not URL-embedded token

Address automated security review of 6582e3c: embedding oauth2:<token>@ in the
import-cache clone URL persisted the token into that repo's .git/config
(secret at rest). Revert shallowClone to the non-persisted http.extraHeader,
and give shallowFetch a matching per-invocation extraHeader (new fetchAuthHeader
covers github/gitlab/gitcode) so private-repo incremental fetch still
authenticates without a credential helper — verified live with credential.helper
disabled: fetch succeeds and .git/config contains no token.

The team-repo clone (providers/gitcode/gitcode-api.ts) still embeds the token,
matching github/tgit: its push flow uses a plain git push with no per-command
header, so persisted creds are required there.
2026-09-01 19:47:35 +08:00
..