Skip to content

fix(scm/gitlab): start without credentials instead of panicking - #6644

Open
markphelps wants to merge 3 commits into
v2from
markphelps/fix-gitlab-scm-no-credentials
Open

markphelps wants to merge 3 commits into
v2from
markphelps/fix-gitlab-scm-no-credentials

Conversation

@markphelps

@markphelps markphelps commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Why

With scm.type: gitlab and no scm.credentials, Flipt crashes at startup with a nil pointer dereference in gitlab.NewSCM. The GitLab client is only created when credentials are set, and the code then uses it either way. GitHub, Bitbucket and Gitea all start without credentials and return the SCM's API error if a proposal is attempted. GitLab should behave the same way.

While fixing this, I also found that the "unsupported credential type" error in the Bitbucket, Gitea and GitLab SCMs printed the Go type name (config.CredentialType) instead of the actual value, and the CUE and JSON config schemas marked scm.credentials as required even though the Go config treats it as optional.

What

  • GitLab without credentials: NewSCM now creates an unauthenticated client and still honours api_url, matching Bitbucket and Gitea.
    • The GitLab client library always sets a PRIVATE-TOKEN header, even when the token is empty. A small HTTP transport removes the empty header, so requests without credentials carry no auth header.
  • Error message: Bitbucket, Gitea and GitLab now report the value, e.g. unsupported credential type: "ssh".
  • Config schemas: scm.credentials is now optional in flipt.schema.cue and flipt.schema.json, matching the Go config.

Testing

  • TestNewSCM_NoApiAuth: NewSCM with no credentials returns a usable SCM. It panicked before.
  • TestNewSCM_NoApiAuth_Propose: against a test server returning 401, Propose returns GitLab's 401 error. The request reaches the configured api_url and carries no PRIVATE-TOKEN or Authorization header.
  • TestNewSCM_UnsupportedCredentialType in each of the three packages, using a real SSH credential.
  • Test_SchemaSCMCredentialsOptional: both schemas accept an SCM block with and without credentials.
  • All new tests fail on the old code.
  • Manual check: a dev build with one GitLab environment, no credentials and a stub api_url starts, serves flags and logs no panic. The same config on v2 crashes at gitlab.go:108.
  • mise run lint and mise run go:modernize are clean, go mod tidy makes no changes, and go test -race passes for internal/coss/storage/... and internal/storage/environments/....

…e missing

Signed-off-by: Mark Phelps <209477+markphelps@users.noreply.github.com>
Signed-off-by: Mark Phelps <209477+markphelps@users.noreply.github.com>
@markphelps
markphelps requested a review from a team as a code owner October 5, 2026 20:12
@markphelps markphelps added the v2 Flipt v2 label Oct 5, 2026
Signed-off-by: Mark Phelps <209477+markphelps@users.noreply.github.com>
@codecov

codecov Bot commented Oct 5, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 92.30769% with 1 line in your changes missing coverage. Please review.
✅ Project coverage is 61.93%. Comparing base (8154330) to head (1314a3e).

Files with missing lines Patch % Lines
...nal/coss/storage/environments/git/gitlab/gitlab.go 90.90% 1 Missing ⚠️

❗ There is a different number of reports uploaded between BASE (8154330) and HEAD (1314a3e). Click for more details.

HEAD has 13 uploads less than BASE
Flag BASE (8154330) HEAD (1314a3e)
integrationtests 13 0
Additional details and impacted files
@@            Coverage Diff             @@
##               v2    #6644      +/-   ##
==========================================
- Coverage   69.44%   61.93%   -7.52%     
==========================================
  Files         147      147              
  Lines       13669    13677       +8     
==========================================
- Hits         9493     8471    -1022     
- Misses       4176     5206    +1030     
Flag Coverage Δ
integrationtests ?
unittests 61.93% <92.30%> (+0.32%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@erka erka left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nice!

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

v2 Flipt v2

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

2 participants