Handle gh-aw offline BYOK sentinel in Copilot auth selection for Business/Enterprise targets - #6237
Conversation
There was a problem hiding this comment.
Pull request overview
Updates Copilot API proxy authentication so gh-aw’s offline BYOK sentinel falls back to GitHub-token authentication.
Changes:
- Treats the offline dummy BYOK value as absent.
- Preserves Business/Enterprise
tokenauthorization formatting. - Adds focused unit and auth-matrix regressions.
Show a summary per file
| File | Description |
|---|---|
containers/api-proxy/providers/copilot-auth.js |
Filters the offline BYOK sentinel during credential resolution. |
containers/api-proxy/copilot-auth.test.js |
Tests token fallback and sentinel filtering. |
containers/api-proxy/copilot-adapter-enterprise.test.js |
Covers Business/GHEC authorization formatting. |
containers/api-proxy/server.auth-matrix.test.js |
Aligns credential-isolation expectations. |
Review details
Tip
Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
- Files reviewed: 4/4 changed files
- Comments generated: 0
- Review effort level: Medium
|
✅ Copilot review passed with no inline comments. @copilot Add the |
|
✅ Smoke Claude passed |
|
❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed... |
|
🔑 Smoke Copilot PAT PAT auth validated. All systems operational. ✅ |
|
❌ Security Guard failed. Please review the logs for details. |
|
✅ Build Test Suite completed successfully! |
|
✅ Contribution Check completed successfully! PR #6237 follows the applicable CONTRIBUTING.md guidelines: it includes focused regression tests alongside the container code, uses appropriate file organization, has a clear description, and does not require documentation updates for this internal auth-handling fix. |
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓 |
|
✅ Smoke Gemini completed. All facets verified. 💎 |
|
📰 VERDICT: Smoke Docker Sbx has concluded. All systems operational. This is a developing story. 🎤 |
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅ |
|
❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed... |
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤 |
|
🔌 Smoke Services — All services reachable! ✅ |
|
🌑 The shadows whisper... Smoke Codex failed. The oracle requires further meditation... |
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded. |
|
🐳🔮 Smoke Docker Sbx Codex completed. Docker sbx + Codex smoke test passed. ✅ |
|
🦎🏗️ Smoke gVisor Build Test completed. gVisor build test passed. ✅ |
|
🐳🟣 Smoke Docker Sbx Claude completed. Docker sbx + Claude smoke test passed. ✅ |
|
🦎🔮 Smoke gVisor Codex completed. gVisor + Codex smoke test passed. ✅ |
🔬 Smoke Test Results
Overall: PASS — MCP reachable; pre-computed template vars were unresolved. Author: Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "awmgmcpg"See Network Configuration for more information.
|
Smoke Test: Claude Engine Validation
Overall Result: PASS ✅ Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "awmgmcpg"See Network Configuration for more information.
|
Smoke Test: Services Connectivity
Overall: FAIL — Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "awmgmcpg"See Network Configuration for more information.
|
Smoke Test: Copilot BYOK (Direct) Mode
Running in direct BYOK mode (COPILOT_PROVIDER_API_KEY) via api-proxy → api.githubcopilot.com Overall: FAIL — pre-fetched template variables were not expanded; tests 1–3 unverifiable.
Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "awmgmcpg"See Network Configuration for more information.
|
🦎 gVisor Smoke Test Results
Overall: PASS cc Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "example.com"
- "host.docker.internal"See Network Configuration for more information.
|
|
Thanks for including focused regression coverage and updating the auth matrix. One contribution guideline remains: please reference the related issue in the PR description, as required under CONTRIBUTING.md's Pull Request Process ("Pull request requirements"). If no issue exists, please note that explicitly. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "awmgmcpg"See Network Configuration for more information.
|
🦎🟣 gVisor + Claude Smoke Test
Overall: FAIL (gVisor runtime not confirmed) Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "example.com"
- "host.docker.internal"See Network Configuration for more information.
|
Smoke Test: API Proxy OpenTelemetry Tracing
All 5 scenarios pass. OTEL integration is fully implemented and tested. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "awmgmcpg"See Network Configuration for more information.
|
Smoke Test: Copilot PAT Auth
Overall: PARTIAL — Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "awmgmcpg"See Network Configuration for more information.
|
Smoke Test Results: FAIL
Overall: FAIL Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "localhost"See Network Configuration for more information.
|
🦎🏗️ gVisor Build Test Results
Overall: FAIL Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "host.docker.internal"See Network Configuration for more information.
|
|
🦎🔮 gVisor + Codex runtime: confirmed\n✅ /proc/version gVisor\n✅ file write/read proof\n✅ github.com reachable (200)\n✅ example.com blocked (000)\n❌ GitHub MCP PR listing failed (Squid 403)\nOverall status: FAIL Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "172.30.0.1"
- "example.com"See Network Configuration for more information.
|
Chroot Version Comparison
Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "awmgmcpg"See Network Configuration for more information.
|
🐳🏗️ Docker Sbx Build Test Results
Overall: FAIL
|
🏗️ Build Test Suite Results
Overall: 8/8 ecosystems passed — ✅ PASS Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "awmgmcpg"See Network Configuration for more information.
|
🔥 Smoke Test: Docker Sbx — PASS
Overall: PASS —
|
|
🐳🔮 Docker sbx + Codex
|
🐳🟣 Docker sbx + Claude
Overall: FAIL — non-allowlisted domain example.com was reachable via the proxy tunnel.
|
Smoke Test
Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "awmgmcpg"
- "registry.npmjs.org"See Network Configuration for more information.
|
On GHES/GHEC workflows using
--copilot-api-target api.business.githubcopilot.com, requests could still send a malformed auth header and get400 Authorization header is badly formatted. The remaining gap was that gh-aw’s offline dummy BYOK value was treated as a real provider key, suppressing GitHub-token auth formatting logic.Auth token selection fix (api-proxy)
dummy-byok-key-for-offline-modeas a non-credential sentinel (same class as AWF placeholder tokens).COPILOT_GITHUB_TOKENwhen the dummy BYOK value is present, allowing Business/Enterprise targets to use the expected GitHub token auth format.Regression coverage for the reported path
Added focused cases to assert that with:
COPILOT_API_TARGET=api.business.githubcopilot.comAWF_PLATFORM_TYPE=ghecGITHUB_SERVER_URL=*.ghe.comCOPILOT_PROVIDER_API_KEY=dummy-byok-key-for-offline-modeauth headers are still derived from
COPILOT_GITHUB_TOKEN(not dummy BYOK).Auth matrix alignment