Allow device login to preselect an organization - #975
Conversation
Co-authored-by: Amp <amp@ampcode.com> Amp-Thread-ID: https://ampcode.com/threads/T-01a06015-04b9-70ab-aaba-bc0e8736680f Co-authored-by: Samuel Cochran <sj26@sj26.com>
There was a problem hiding this comment.
I didn't find any code issues. This changes OAuth device-login request behavior, so it sits above this review's L1 approval ceiling and I'm leaving a comment rather than an approval.
Want to dig deeper?
Paste this into your agent to explore the findings from this review's Buildkite build:
Download the buildsworth logs from build 24124, then answer my questions about the findings.
Install the reading-buildsworth-logs skill to run this.
About buildsworth
Model: gpt-5.6-sol with xhigh thinking.
How to request a review: Comment @buildsworth-bk review on the PR, or request buildsworth-bk as a reviewer.
Risk labels (how buildsworth classifies risk) — buildsworth classifies risk itself from the diff. Unless repository policy already allows L2 approval, grant it by mentioning @buildsworth-bk (see approval ceiling and L2 approval grant):
- L1 — Low risk (dep bumps, docs/copy, lockfiles, small presentational fixes). buildsworth may approve by default.
- L2 — Standard risk (new UI, additive API fields, refactors). Approved only when repository policy or a verified grant allows it; otherwise comment-only.
- L3 — High risk (auth, migrations, payments, secrets, perf-critical pipeline paths). Human review always required.
|
@buildsworth-bk review, approve L2 |
Description
bk auth login --devicecurrently rejects--org, so multi-organization users must select the intended organization manually in the browser.Allow device login to send the same organization slug or UUID hint that browser-based login already supports:
Requires the additive device authorization endpoint support in https://github.com/buildkite/buildkite/pull/33566. Older endpoints safely ignore the hint. User documentation is in buildkite/docs#3159.
Changes
--deviceand--orgto be used together.organizationororganization_uuidwith the device authorization request.Testing
mise run format).mise run lintpasses.go test ./...is blocked locally by the existingTestCmdSwitchfailures, which reproduce when that untouched test runs alone.Disclosures / Credits
Amp investigated, implemented, reviewed, and tested this change under my direction.