docs(repo): clarify entire:// passthrough deliberately skips host validation · Entire

docs(repo): clarify entire:// passthrough deliberately skips host validation

1fc19a0→main·

toothbrush·2w ago·1 file·+7 added/-0 removed

The verbatim entire:// URL is forwarded to git clone exactly as typed (equivalent to a raw `git clone entire://…`); validateClusterHost only guards the shorthand path where we synthesize the URL ourselves.

Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com

Sessions

6e00001035ccView transcript

Changes

1

95 unmodified lines

96
97
98
99
100
101
102
103
104
105
106
107
108

95 unmodified lines

// A full entire:// clone URL already embeds the cluster host (it's what
// --cluster would otherwise resolve to), so pass it verbatim to git clone
// — no mirror lookup or cluster resolution. --cluster is irrelevant here.
//
// Deliberately NOT run through validateClusterHost: this is a raw URL the
// user typed, forwarded to `git clone` exactly as given (the whole point
// of this branch), so it's equivalent to running `git clone entire://…`
// directly. The validateClusterHost guard applies on the shorthand path
// where we *synthesize* the URL from a --cluster flag or an API-supplied
// host — values that flow into the STS audience under our own construction.
if isEntireCloneURL(ref) {
    return runGitClone(cmd.Context(), cmd, ref, targetDir)
}

Mcmd/entire/cli/repo_clone.go+7