Currently, users who need multiple repos for development must use complex workarounds to get the right level of permissions and scopes they need to be work productively within their main project repository.
Soon, customers will be able to specify finer grained permissions & scopes that a codespace needs as part of their configuration setup.
Intended Outcome
Rather than forcing users to navigate Codespace defaults, options, and custom PATs to get the right set of permissions and scopes to leverage other repositories their main project needs, users will soon be able to specify the exact set of permissions and scopes they need as part of the devcontainer.json.
How will it work?
We allow users to customize codespace permissions in devcontainer.json via a codespaces.repositories property:
On create, we look to see if the user has the appropriate permissions to create the codespace. For example, if the devcontainer requires read access to a specific repo that the user does not have access to, creation will fail as the resulting codespace will not have the complete set of required repositories needed to successfully run the project.
Additionally, on create and start we will check whether the user has previously accepted the current set or a superset of the current permissions for the repository. If they have then create/start continues. If not, they are sent through an acceptance flow similar to the GitHub App authorization flow, showing the user the repositories and scopes to be used within the codespace.
The text was updated successfully, but these errors were encountered:
Summary
Currently, users who need multiple repos for development must use complex workarounds to get the right level of permissions and scopes they need to be work productively within their main project repository.
Soon, customers will be able to specify finer grained permissions & scopes that a codespace needs as part of their configuration setup.
Intended Outcome
Rather than forcing users to navigate Codespace defaults, options, and custom PATs to get the right set of permissions and scopes to leverage other repositories their main project needs, users will soon be able to specify the exact set of permissions and scopes they need as part of the devcontainer.json.
How will it work?
We allow users to customize codespace permissions in devcontainer.json via a codespaces.repositories property:

On create, we look to see if the user has the appropriate permissions to create the codespace. For example, if the devcontainer requires read access to a specific repo that the user does not have access to, creation will fail as the resulting codespace will not have the complete set of required repositories needed to successfully run the project.
Additionally, on create and start we will check whether the user has previously accepted the current set or a superset of the current permissions for the repository. If they have then create/start continues. If not, they are sent through an acceptance flow similar to the GitHub App authorization flow, showing the user the repositories and scopes to be used within the codespace.
The text was updated successfully, but these errors were encountered: