BUG 🐛: GitHub Sprite Connector 404 path

When clicking "Continue with Github: button when “Adding first Connector” in the fly.io web UI dashboard for Sprites - it leads to a “Error 404 Well this is embarrassing…” error. The expected permissions/connection approval screen on GitHub.com isn’t redirected to.

Please update this topic when fixed. “All good” shown for the current Statuses report.

Thanks for catching that @mountainash, it seems adding OAuth based connectors are snagged at the moment, I’ve reported brought this up internally and will update this when its fixed :slight_smile:

Hey @mountainash, should be fixed now if you give it a shot :slight_smile:

Thank you @michaelp - I can confirm that the 404 flow has now been fixed. But can I request that you change the connectors scope - it seems very excessive for the use cases of Sprites.

Currently:
This application will be able to read and write all public and private repository data. This includes the following:

  • Code

  • Issues

  • Pull requests

  • Wikis

  • Settings

  • Webhooks and services

  • Deploy keys

  • Collaboration invites

The biggest issue I have is that I have to allow all my repositories. Please change it so that individual GH project access can be allowed (not ALL).

Hello @mountainash–Thanks for confirming that the 404 issue has been fixed–appreciate it!

That’s a fair point. I’ll raise a request to review the current Github connector scope to the sprites team, particularly, to change the access scope to only selected GH projects.

Any updates on the reduction of permissions and limiting of projects?

I don’t disagree with your scope change request, but in the interim, could you set up an auto-syncing clone in a different account? It might achieve your security objective now, even at the cost of some hassle.

That’s one (complex) idea… but a much easier workaround is just not using the connector feature at all and creating a session directly within the Sprite.

Hello @montainash and @halfer! Thanks for your patience on this request, and thank you for your suggestions.

The request has been raised, but there’s currently no ETA just yet. Rest assured that we’ll keep you posted once we have more updates to share.