fix(repo): address clone review nits · Entire
fix(repo): address clone review nits
3614bbf·
toothbrush·3w ago·2 files·+20 added/-6 removed
- error message matches accepted ref form (leading slash optional)
- self-contained github provider const (drop checkpoint-named borrow)
- not-found hint uses canonical /gh/
/ - validate server-provided cluster host before building the clone URL
- update repo group doc comment now that clone lives there
Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com
Sessions
5cb16b9c7fccView transcript
Changes
2
cmd/entire/cli
Mrepo.go+4/-3
- Mrepo_clone.go+16/-3
12 unmodified lines
13
14
15
16
17
18
16
17
18
19
20
21
22
12 unmodified lines
// newRepoCmd is the hidden `entire repo` command group: control-plane
// repository lifecycle (create, list within a project, get, delete) on the
// Entire control plane. Git content operations (clone, log, diff, …) are
// intentionally out of scope here. Surfaced via `entire labs`.
// repository lifecycle (create, list within a project, get, delete) plus the
// `clone` convenience that resolves a mirror and shells out to `git clone`.
// Other git content operations (log, diff, …) remain intentionally out of scope
// here. Surfaced via `entire labs`.
func newRepoCmd() *cobra.Command {
cmd := &cobra.Command{
Use: "repo",
Mcmd/entire/cli/repo.go+4/-3
22 unmodified lines
// (owner/repo flow unescaped into the synthesised entire:// clone URL).
var mirrorCloneRefRe = regexp.MustCompile(`^/?gh/` + gitHubOwnerPat + `/` + gitHubRepoPat + `$`)
// mirrorCloneProviderGitHub is the upstream provider the `gh` path token maps to
// — the value the control plane records and the list API filters on. Kept local
// to the clone path so the provider mapping is self-contained rather than
// borrowing a constant named for an unrelated (checkpoint) concern.
const mirrorCloneProviderGitHub = "github"
// parseMirrorCloneRef turns a clone ref like `/gh/entirehq/entire-api` into the
// API provider ("github") and the lowercased owner/repo. The `gh` token is the
// path provider used in entire:// clone URLs; it maps to the "github" upstream
1 unmodified line
func parseMirrorCloneRef(ref string) (provider, owner, repo string, err error) {
m := mirrorCloneRefRe.FindStringSubmatch(strings.TrimSpace(ref))
if m == nil {
return "", "", "", fmt.Errorf("expected /gh/<owner>/<repo>, got %q", ref)
return "", "", "", fmt.Errorf("expected gh/<owner>/<repo> (leading slash optional), got %q", ref)
}
owner, repo = strings.ToLower(m[1]), strings.ToLower(m[2])
if gitHubDotOnlyRe.MatchString(repo) {
return "", "", "", fmt.Errorf("repo cannot be dot-only: %s", ref)
}
return checkpointProviderGitHub, owner, repo, nil
return mirrorCloneProviderGitHub, owner, repo, nil
}
// newCloneAliasCmd is the top-level `entire clone` alias for `entire repo
63 unmodified lines
}
if len(mirrors) == 0 {
return fmt.Errorf("no mirror found for gh/%s/%s; run 'entire repo mirror create github.com/%s/%s' to onboard it", owner, repo, owner, repo)
return fmt.Errorf("no mirror found for /gh/%s/%s; run 'entire repo mirror create github.com/%s/%s' to onboard it", owner, repo, owner, repo)
}
chosen, err := selectCloneTarget(cmd, mirrors, cluster)
1 unmodified line
return err
}
// chosen.ClusterHost is server-provided, but it's interpolated into the
// entire:// clone URL just like the user-supplied --cluster, so apply the
// same anti-token-leak guard (validateClusterHost) before building it —
// defense-in-depth against a malformed host reaching git / the STS audience.
if err := validateClusterHost(chosen.ClusterHost); err != nil {
return fmt.Errorf("mirror has an invalid cluster host %q: %w", chosen.ClusterHost, err)
}
cloneURL := fmt.Sprintf("entire://%s/gh/%s/%s", chosen.ClusterHost, owner, repo)
return runGitClone(cmd.Context(), cmd, cloneURL, targetDir)
},