2 months ago
68d3ae9Marketplace/plugin/skill fetches only authenticated via GITHUB_TOKEN/GH_TOKEN env vars, so desktop-app launches (no shell env) always hit the anonymous 60/hr GitHub API limit — quickly exhausted by per-directory Contents API calls during installs. - Add resolveGitHubToken(): env vars, then `gh auth token`, then non-interactive `git credential fill`, cached per process. - Attach the token to all GitHub API/raw fetches (extensions, marketplace manifest raw fallback, Codex release metadata) via fetchWithGitHubAuth. - Guard: locally resolved tokens are only sent to GitHub-owned hosts, and a 401/403 with local credentials retries anonymously so stale tokens never break public-repo access. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Parentec9ccb4