Files
VasuBansal7576andPeter Steinberger 104e67f55e fix(auth): preserve Copilot tenant credentials during Doctor repair (#139131)
* fix(auth): preserve Copilot tenant credentials during Doctor repair

* test(auth): split Copilot ownership cases below file-size limit

* docs(copilot): clarify tenant credential sharing

Document that agents share Copilot credentials only when supported tenant scopes
match, and direct affected agents to authenticate for their intended tenant.

Co-authored-by: VasuBansal <148481383+VasuBansal7576@users.noreply.github.com>

* fix(auth): preserve Copilot tenant fences during peer settlement

Require refreshed shared Copilot credentials to match the fenced peer's
normalized routing scope before local fence removal. Cross-tenant peers remain
terminally fenced.

Co-authored-by: VasuBansal <148481383+VasuBansal7576@users.noreply.github.com>

* fix(auth): preserve Copilot tenant scope in ownership

Require Copilot OAuth ownership to validate normalized routing scope before
accepting an identical refresh generation. Same-tenant peers keep the shared
owner shortcut while cross-tenant credentials remain locally owned.

Co-authored-by: VasuBansal <148481383+VasuBansal7576@users.noreply.github.com>

* test(gateway): await plugin application receipt

* test(gateway): await node terminal events

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: VasuBansal <148481383+VasuBansal7576@users.noreply.github.com>
2026-09-24 17:40:17 -07:00

3 lines
148 B
TypeScript

/** Pure provider-owned credential scope policy shared with core auth ownership. */
export { normalizeGithubCopilotOAuthScope } from "./domain.js";