Skip to main content

ShellCredentials

Struct ShellCredentials 

Source
pub struct ShellCredentials {
    pub gh: Option<bool>,
    pub git: Option<bool>,
}
Expand description

Command-scoped GitHub credential injection for the shell commands an agent runs.

Each channel is opt-in and independent, and injection is scoped to the individual command spawn: the credential is resolved from the session’s current authentication at every spawn and reaches only spawns whose script actually invokes git or gh. Because nothing is retained between spawns, replacing the session credential (session.gitHubAuth.setCredentials) changes what the next spawned command presents — which seeding a credential into the runtime process’s own environment cannot do, since a child’s environment is fixed at exec.

The credential is matched to the host it authenticates to, so a github.com credential is never presented to a GitHub Enterprise host and vice versa. Where a channel cannot express that boundary it injects nothing rather than crossing it – see gh below.

This is independent of sandboxConfig: it is a decision about which identity the agent presents, not about what the agent may touch, and it works on every platform whether or not an OS sandboxing backend is available. sandboxConfig.auth remains the sandbox-scoped spelling and is additive with this one.

Experimental. This type is part of an experimental wire-protocol surface and may change or be removed in future SDK or CLI releases.

Fields§

§gh: Option<bool>

Whether to authenticate the agent’s gh commands as the session’s GitHub credential, by exporting GH_TOKEN to a spawn that runs gh. Any inherited gh credential is removed from spawns that do not, so the credential stays command-scoped.

Applies to a github.com credential only. gh picks its credential variable from the host a command targets rather than the one the credential belongs to, and the command can choose that target, so GH_ENTERPRISE_TOKEN would offer a single-tenant enterprise credential to every other enterprise host. A session whose credential is enterprise-scoped therefore runs gh unauthenticated; its git commands are unaffected, because http.<host>.extraheader is scoped to one host by construction. Default: false (opt-in).

§git: Option<bool>

Whether to authenticate the agent’s git commands as the session’s GitHub credential, by injecting an http.<host>.extraheader (plus insteadOf rewrites so SSH-spelled remotes for that host use the authenticated HTTPS transport). Applied only to a spawn that runs a remote-contacting git subcommand. Default: false (opt-in).

Trait Implementations§

Source§

impl Clone for ShellCredentials

Source§

fn clone(&self) -> ShellCredentials

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for ShellCredentials

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for ShellCredentials

Source§

fn default() -> ShellCredentials

Returns the “default value” for a type. Read more
Source§

impl<'de> Deserialize<'de> for ShellCredentials

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Serialize for ShellCredentials

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more