INNER CODE UNIT · Python

owner

mrwadams/stride-gpt · apps/web/main.py:540

    owner = parts[-2]
    repo_name = parts[-1]

    # Only send the GitHub token to github.com or a host the operator explicitly
    # allowlists via STRIDE_GPT_GHE_HOST — anything else would leak credentials.
    hostname = (parsed_url.hostname or "").lower()
    ghe_host = os.getenv("STRIDE_GPT_GHE_HOST", "").strip().lower()
    token = st.session_state.get("github_api_key", "")

    if hostname == "github.com":
        g = Github(token)
    elif ghe_host and hostname == ghe_host:
        g = Github(token, base_url=f"https://{hostname}/api/v3")
    else:
        raise ValueError(
            f"Refusing to send GitHub token to '{hostname or repo_url}'. "
            "Only github.com is allowed by default; set STRIDE_GPT_GHE_HOST to "
            "your GitHub Enterprise hostname to permit it."

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…