Remove the Entire DB credential-store integration · Entire
Review of Code Changes
Review the code changes against the base branch 'main'. The merge base commit for this comparison is 368750cee35f31935640a34ad199e889fc60f1a8. Run git diff 368750cee35f31935640a34ad199e889fc60f1a8 to inspect the changes relative to main. Provide prioritized, actionable findings.
Findings
- Title: [P2] Implement real locking for Windows file token writes
Body: WhenENTIRE_TOKEN_STORE=fileis used on Windows,flockExclusiveonly opens the lock file and does not exclude another process.writeFileTokenrelies on this lock for its read-modify-write and also writes to a fixedpath + ".tmp"before renaming, so two concurrent logins or credential refreshes can overwrite each other's temp file, lose one credential, or return a rename error. Please use a real Windows interprocess lock, or otherwise make concurrent writes safe.
Confidence Score: 0.87
Priority: 2
Code Location:- Absolute File Path:
/Users/soph/Work/entire/devenv/git-sync/internal/auth/tokenstore_lock_windows.go - Line Range: 20-20
- Absolute File Path:
Overall Correctness
- Overall Correctness: patch is incorrect
- Overall Explanation: The patch fixes Windows compilation, but the Windows lock implementation is a no-op while the token store write path still depends on mutual exclusion for correctness under concurrent file-store writes.
- Overall Confidence Score: 0.87
Additional Notes
Remove the Entire DB credential-store integration.
git-sync carried a bespoke Entire credential path: auth.Resolve fell back to an active-user lookup in ~/.config/entire/hosts.json plus a file/keyring token store and OAuth refresh-token handling (client_id=entire-cli). Nothing in the product produces that layout anymore — the mirror-pipeline worker supplies credentials directly at the transport layer (GitHub installation tokens + per-request entire-core repo-scoped bearers), and client-side entire:// auth is owned by the separate git-remote-entire helper using the newer contexts.json model.Drop
entiredb.goandtokenstore.goand theLookupEntireDBCredentialfallback;auth.Resolvenow resolves explicit token/bearer credentials only and otherwise returns nil so the git credential helper is consulted on a 401. This also drops thegithub.com/zalando/go-keyringdependency and removes thesyscall.Flockusage that broke the Windows build, ensuring that the package now cross-compiles for Windows cleanly.Supersedes the entiredb token-refresh fix (#90) and the tokenstore Windows flock fix (#92), both of which were polishing this now-deleted code.