diff --git a/cli/gitauth/vscode.go b/cli/gitauth/vscode.go index fbd2265192..daaf64c827 100644 --- a/cli/gitauth/vscode.go +++ b/cli/gitauth/vscode.go @@ -19,12 +19,18 @@ func OverrideVSCodeConfigs(fs afero.Fs) error { return err } mutate := func(m map[string]interface{}) { - // This prevents VS Code from overriding GIT_ASKPASS, which - // we use to automatically authenticate Git providers. - m["git.useIntegratedAskPass"] = false - // This prevents VS Code from using it's own GitHub authentication - // which would circumvent cloning with Coder-configured providers. - m["github.gitAuthentication"] = false + // These defaults prevent VS Code from overriding + // GIT_ASKPASS and using its own GitHub authentication, + // which would circumvent cloning with Coder-configured + // providers. We only set them if they are not already + // present so that template authors can override them + // via module settings (e.g. the vscode-web module). + if _, ok := m["git.useIntegratedAskPass"]; !ok { + m["git.useIntegratedAskPass"] = false + } + if _, ok := m["github.gitAuthentication"]; !ok { + m["github.gitAuthentication"] = false + } } for _, configPath := range []string{ diff --git a/cli/gitauth/vscode_test.go b/cli/gitauth/vscode_test.go index 7bff62fafd..fd4762c33b 100644 --- a/cli/gitauth/vscode_test.go +++ b/cli/gitauth/vscode_test.go @@ -61,4 +61,31 @@ func TestOverrideVSCodeConfigs(t *testing.T) { require.Equal(t, "something", mapping["hotdogs"]) } }) + t.Run("NoOverwrite", func(t *testing.T) { + t.Parallel() + fs := afero.NewMemMapFs() + mapping := map[string]interface{}{ + "git.useIntegratedAskPass": true, + "github.gitAuthentication": true, + "other.setting": "preserved", + } + data, err := json.Marshal(mapping) + require.NoError(t, err) + for _, configPath := range configPaths { + err = afero.WriteFile(fs, configPath, data, 0o600) + require.NoError(t, err) + } + err = gitauth.OverrideVSCodeConfigs(fs) + require.NoError(t, err) + for _, configPath := range configPaths { + data, err := afero.ReadFile(fs, configPath) + require.NoError(t, err) + mapping := map[string]interface{}{} + err = json.Unmarshal(data, &mapping) + require.NoError(t, err) + require.Equal(t, true, mapping["git.useIntegratedAskPass"]) + require.Equal(t, true, mapping["github.gitAuthentication"]) + require.Equal(t, "preserved", mapping["other.setting"]) + } + }) }