mirror of
https://github.com/OpenHands/OpenHands.git
synced 2026-10-07 13:58:33 +08:00
163 lines
5.6 KiB
Python
163 lines
5.6 KiB
Python
import json
|
|
from typing import Any, cast
|
|
|
|
import httpx
|
|
from pydantic import SecretStr
|
|
|
|
from openhands.app_server.integrations.protocols.http_client import HTTPClient
|
|
from openhands.app_server.integrations.service_types import (
|
|
BaseGitService,
|
|
RequestMethod,
|
|
UnknownException,
|
|
User,
|
|
)
|
|
from openhands.app_server.utils.http_session import httpx_verify_option
|
|
from openhands.app_server.utils.logger import openhands_logger as logger
|
|
|
|
|
|
class GitHubMixinBase(BaseGitService, HTTPClient):
|
|
"""
|
|
Declares common attributes and method signatures used across mixins.
|
|
"""
|
|
|
|
BASE_URL: str
|
|
GRAPHQL_URL: str
|
|
|
|
@staticmethod
|
|
def _resolve_primary_email(emails: list[dict]) -> str | None:
|
|
"""Find the primary verified email from a list of GitHub email objects.
|
|
|
|
GitHub's /user/emails endpoint returns a list of dicts, each with
|
|
'email', 'primary', and 'verified' keys. This selects the one marked
|
|
as both primary and verified — the email the user considers canonical.
|
|
"""
|
|
for entry in emails:
|
|
if entry.get('primary') and entry.get('verified'):
|
|
return entry.get('email')
|
|
return None
|
|
|
|
async def _get_headers(self) -> dict:
|
|
"""Retrieve the GH Token from settings store to construct the headers."""
|
|
if not self.token:
|
|
latest_token = await self.get_latest_token()
|
|
if latest_token:
|
|
self.token = latest_token
|
|
|
|
return {
|
|
'Authorization': f'Bearer {self.token.get_secret_value() if self.token else ""}',
|
|
'Accept': 'application/vnd.github.v3+json',
|
|
}
|
|
|
|
async def get_latest_token(self) -> SecretStr | None: # type: ignore[override]
|
|
return self.token
|
|
|
|
async def _make_request(
|
|
self,
|
|
url: str,
|
|
params: dict | None = None,
|
|
method: RequestMethod = RequestMethod.GET,
|
|
) -> tuple[Any, dict]: # type: ignore[override]
|
|
try:
|
|
async with httpx.AsyncClient(verify=httpx_verify_option()) as client:
|
|
github_headers = await self._get_headers()
|
|
|
|
# Make initial request
|
|
response = await self.execute_request(
|
|
client=client,
|
|
url=url,
|
|
headers=github_headers,
|
|
params=params,
|
|
method=method,
|
|
)
|
|
|
|
# Handle token refresh if needed
|
|
if self.refresh and self._has_token_expired(response.status_code):
|
|
await self.get_latest_token()
|
|
github_headers = await self._get_headers()
|
|
response = await self.execute_request(
|
|
client=client,
|
|
url=url,
|
|
headers=github_headers,
|
|
params=params,
|
|
method=method,
|
|
)
|
|
|
|
response.raise_for_status()
|
|
headers: dict = {}
|
|
if 'Link' in response.headers:
|
|
headers['Link'] = response.headers['Link']
|
|
|
|
return response.json(), headers
|
|
|
|
except httpx.HTTPStatusError as e:
|
|
raise self.handle_http_status_error(e) from e
|
|
except httpx.HTTPError as e:
|
|
raise self.handle_http_error(e) from e
|
|
|
|
async def execute_graphql_query(
|
|
self, query: str, variables: dict[str, Any]
|
|
) -> dict[str, Any]:
|
|
try:
|
|
async with httpx.AsyncClient(verify=httpx_verify_option()) as client:
|
|
github_headers = await self._get_headers()
|
|
|
|
response = await client.post(
|
|
self.GRAPHQL_URL,
|
|
headers=github_headers,
|
|
json={'query': query, 'variables': variables},
|
|
)
|
|
response.raise_for_status()
|
|
|
|
result = response.json()
|
|
if 'errors' in result:
|
|
raise UnknownException(
|
|
f'GraphQL query error: {json.dumps(result["errors"])}'
|
|
)
|
|
|
|
return dict(result)
|
|
|
|
except httpx.HTTPStatusError as e:
|
|
raise self.handle_http_status_error(e) from e
|
|
except httpx.HTTPError as e:
|
|
raise self.handle_http_error(e) from e
|
|
|
|
async def get_user_emails(self) -> list[dict]:
|
|
"""Fetch the authenticated user's email addresses from GitHub.
|
|
|
|
Calls GET /user/emails which returns a list of email objects, each
|
|
containing 'email', 'primary', 'verified', and 'visibility' fields.
|
|
Requires the user:email OAuth scope.
|
|
"""
|
|
url = f'{self.BASE_URL}/user/emails'
|
|
response, _ = await self._make_request(url)
|
|
return response
|
|
|
|
async def verify_access(self) -> bool:
|
|
url = f'{self.BASE_URL}'
|
|
await self._make_request(url)
|
|
return True
|
|
|
|
async def get_user(self):
|
|
url = f'{self.BASE_URL}/user'
|
|
response, _ = await self._make_request(url)
|
|
|
|
email = response.get('email')
|
|
if email is None:
|
|
try:
|
|
emails = await self.get_user_emails()
|
|
email = self._resolve_primary_email(emails)
|
|
except Exception:
|
|
logger.warning(
|
|
'github:get_user:email_fallback_failed',
|
|
exc_info=True,
|
|
)
|
|
|
|
return User(
|
|
id=str(response.get('id', '')),
|
|
login=cast(str, response.get('login') or ''),
|
|
avatar_url=cast(str, response.get('avatar_url') or ''),
|
|
company=response.get('company'),
|
|
name=response.get('name'),
|
|
email=email,
|
|
)
|