// the find
Anish-Agnihotri/GateRepo
Token-gated repositories via GitHub API.
GateRepo lets a repository owner require an ERC20 balance before a GitHub user is invited as a collaborator. The owner creates a gate with a contract address, a token threshold, and an invite cap, and the app checks a signed wallet message and the token balance before sending the invite through the GitHub API. It's a small Next.js and Postgres project for experimenting with token-gated access, not production access control.
- The balance check runs at the block number recorded when the gate was created, so buying tokens after the gate goes live doesn't grant access.
- Wallet ownership is verified with a signed message before the balance check, so a requester can't claim an address they don't control.
- The access path is written out as a numbered 12-step sequence, which makes it easy to check the handler in pages/api/gates/access.ts against the stated design.
- The limitations are listed in the README instead of left for users to discover: the 50-invites-per-day GitHub cap, no revocation when tokens leave the wallet, and ERC20-only support.
- The last push was April 2022 and nothing has changed since. Expect the Next.js, NextAuth, Prisma, and ethers dependencies to be years behind, and the GitHub OAuth flow may need rework before it runs cleanly today.
- Access is granted once and never rechecked. A user who sells the tokens keeps collaborator access, and the README hands that problem to whoever forks it.
- The OAuth scopes are `repo,read:user,user:email`. `repo` gives full read and write access to every private repo the user can reach, which is a hard sell to anyone who will be asked to log in. The author says so in the README.
- One address can back several GitHub accounts, so a single token holder can open the gate for multiple users. Enforcing one-to-one would mean tracking address-to-gate in the database, which the code doesn't do.