Skip to content

github-integrate: Implement OAuth Device Flow & Keychain Credential Storage (Phase 1) #162

Description

@kavix

Goal

Provide a secure and seamless way for Eko to authenticate with GitHub without exposing plain-text developer credentials.

Steps to Outcome

  1. GitHub OAuth Integration:
    • Register a GitHub OAuth App or specify client ID/secret.
    • Implement the OAuth Device Flow inside the Eko CLI (e.g. eko auth login).
    • The CLI prints a user code and opens the browser for authorization.
  2. Secure Token Storage:
    • Use the github.com/zalando/go-keyring library to interact with native OS keychains (macOS Keychain, Linux Secret Service, Windows Credential Manager).
    • Securely store the returned access token under the service name eko-github.
  3. GitHub API Client Setup:
    • Initialize the google/go-github client with the retrieved access token.
    • Add a diagnostic helper eko auth status to check connection status and scopes.

Final Outcome

Developers can run eko auth login to link Eko to their GitHub account, storing credentials securely in the OS keychain for all subsequent remote API requests.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    github-integrateGitHub remote storage integration

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions