You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Laravel项目迁GitHub后Heroku构建鉴权失败问题排查

Fixing Composer GitHub Authentication Failures on Heroku Pre-Release Apps After BitBucket → GitHub Migration

Hey there, let's break down why this is happening and how to fix it:

First off: Yes, you'll likely need to ensure your new pre-release app has a valid GitHub OAuth token configured—but let's not jump straight to generating a new one. Let's walk through the checks and fixes step by step:

1. Verify Your Existing Token's Validity & Permissions

First, head over to your GitHub account settings:

  • Go to Settings > Developer settings > Personal access tokens (or Fine-grained tokens if you're using the newer, more secure option)
  • Locate the token you were using before:
    • Check if it's expired (classic tokens don't auto-expire by default, but fine-grained ones do)
    • Make sure it has the repo scope enabled (if your dependencies are private GitHub repos). For fine-grained tokens, confirm it has read access to all the GitHub repos your project depends on—especially any you moved to your new GitHub org/account during the migration.

2. Check Heroku Pre-Release App Config Vars

Chances are your original production app used a Heroku environment variable COMPOSER_AUTH to handle Composer authentication (instead of committing auth.json to repo, which is the safer approach). Pre-release apps in Heroku pipelines don't automatically inherit all config vars from production, so:

  • Open your Heroku dashboard, navigate to your pre-release app, go to Settings > Config Vars
  • Look for the COMPOSER_AUTH variable. Its value should be a JSON string like:
    {"github-oauth": {"github.com": "your-valid-token-here"}}
    
  • If it's missing, copy it directly from your production app, or manually add it with your valid token.

3. Stop Committing auth.json to Repo (Critical!)

If you had auth.json checked into your BitBucket/GitHub repo, that's a security risk, and it might be why your pre-release app is picking up an old/invalid token. Do this right away:

  • Add auth.json to your .gitignore file to prevent accidental commits in the future
  • Rely entirely on Heroku's COMPOSER_AUTH config var for Composer auth—this way all apps in your pipeline (pre-release, production, etc.) use the same secure configuration.

4. Generate a New Token If Needed

If your old token is expired, lacks permissions for your new GitHub repos, or you want to lock down permissions further:

  • Create a Fine-grained personal access token (GitHub's recommended option now):
    • Restrict it to only the specific GitHub repos your project depends on
    • Grant only the Contents (read) permission—follow the principle of least privilege
    • Set a reasonable expiration date for added security
  • Update the COMPOSER_AUTH var in your pre-release app (and any other related apps) with this new token.

5. Test the Build

Once everything's configured, trigger a new build in your Heroku pipeline or push a small change to your pre-release branch to test if the authentication error is resolved.

Quick note: Heroku pipeline apps don't inherit config vars automatically, so always double-check critical vars like COMPOSER_AUTH, database credentials, etc., when setting up new pre-release or review apps.

内容的提问来源于stack exchange,提问作者Joshua Foxworth

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 10:31:10