* authentication: enable multiple configured enterprise hosts
Enable unordered enterprise host configuration, host-qualified account selection, and the extension-owned sign-in picker on top of the reviewed engine lifecycle and credential storage layers. Wire trust-aware enrollment and retain the complete eligible session list for platform account preferences.
Part of #277435.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: restore enterprise URL correction during setup
Validate configured instance URLs before starting authentication. Reuse enterprise input parsing across setup and onboarding, allow cloud and server URLs, and replace only the selected invalid entry while preserving current hosts. Cover cancellation, multiple corrections, keyboard focus, and changes made while the prompt is open.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: use the legacy enterprise setting in web builds
Default the enterprise enrollment setting to github-enterprise.uri when browser product metadata omits it. An empty key reads the whole configuration object and broke the legacy-only correction test in every browser CI job. Verified the failure before the fix and the affected suites in Chromium, WebKit and Electron afterward.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: preserve native enterprise session identities
Remove facade ID prefixes and session rewriting. Create account labels in the host engine, showing the instance only for multiple configured hosts and updating cached presentation without recreating engines or rewriting usernames in storage. Route native IDs using session provenance and cached ownership, preserve broker flows, and cover colliding account IDs through core RPC tests. Use async/await for configuration refresh error handling.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* chat: keep Copilot enterprise enrollment on GHE.com
Restore GHE.com-only names and HTTPS URLs in Copilot setup and onboarding, including their examples and validation messages. Keep the generic enterprise authentication provider and configured-URI validation compatible with GHES, and preserve correction and cancellation behavior.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* chat: enroll a cloud instance when only GHES is configured
Require a GHE.com instance before proceeding with Copilot setup while leaving existing GHES authentication configuration intact. Cover both the quick-input and onboarding paths without choosing a default host.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: keep enterprise account labels stable
Always include the host in enterprise account labels under the fixed GitHub Enterprise provider label. Derive the label suffix once from the engine host and remove the suffix setter, cached relabeling and host-count flags. Preserve native IDs, stored usernames and public GitHub labels; verify menu labels across host additions and removals.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: separate enterprise provider and engine lifecycles
Keep the single configured enterprise instance and native account identities, while owning engine replacement, registration-safe session events and cleanup separately. Isolate OAuth callbacks by host and preserve the current Microsoft-brokered flows.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: discard superseded enterprise startup failures
Version enterprise configuration updates so a failed initial update cannot enqueue an error state after a newer configuration succeeds. Cover both A-to-B and A-to-B-to-A races through extension activation while preserving current-error fallback and later recovery.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: serialize enterprise failures and session publication
Remove activation generation bookkeeping by handling failure state inside each queued update. Reconcile preparation-time session removals, additions and changes before publishing a replacement, with regression coverage for consecutive initialization failures and pending-host events.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: own event buffering at the registration boundary
Buffer initial provider events in the extension host until its registration RPC completes. Remove the extension-side wrapper, microtask readiness inference and construction factory; directly construct a host-bound session engine with a side-effect-free cached session inventory. Preserve broker flows and exercise registration ordering through core RPC tests.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: clarify disposal and registration ownership
Keep the bundled README focused on user setup. Name disposal cancellation explicitly, verify cleanup while an engine is still being prepared, and clarify why core captures session events before awaiting registration.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: Add GitHub session issuer provenance
Expose optional session authorizationServer metadata through authIssuers and authentication RPCs, populate it for GitHub sessions, and route in-repository consumers from the selected session. Keep existing single-host configuration and account-selection behavior.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: Preserve public static-token MCP sessions
Keep issuer validation on the enterprise MCP path and preserve the fixed public endpoint for static-token authentication. Cover definition creation and resolution using StaticGitHubAuthenticationService.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* i18n: Register workbench GitHub service translations
Register the service's new localized authentication error with the workbench translation project so the CI translation-reminder rule passes.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>