I try to review this repo at least once a week. Examples of
representing a project or community include using an official project e-mail
address, posting via an official social media account, or acting as an appointed
representative at an online or offline event. Representation of a project may be
further defined and clarified by project maintainers.

## Enforcement

Instances of abusive, harassing, or otherwise unacceptable behavior may be
reported by contacting the project team at . All
complaints will be reviewed and investigated and will result in a response that
is deemed necessary and appropriate to the circumstances. The project team is
obligated to maintain confidentiality with regard to the reporter of an incident.
Further details of specific enforcement policies may be posted separately.

Project maintainers who do not follow or enforce the Code of Conduct in good
faith may face temporary or permanent repercussions as determined by other
members of the project's leadership.

## Attribution

This Code of Conduct is adapted from the [Contributor Covenant][homepage], version 1.4,
available at [http://contributor-covenant.org/version/1/4][version]

[homepage]: http://contributor-covenant.org
[version]: http://contributor-covenant.org/version/1/4/ Your help is essential for keeping it great.

Contributions to this project are [released](https://help.github.com/articles/github-terms-of-service/#6-contributions-under-repository-license) to the public under the [project's open source license](LICENSE).

Please note that this project is released with a [Contributor Code of Conduct](CODE_OF_CONDUCT.md). By participating in this project you agree to abide by its terms.

## Submitting a pull request

1. Fork and clone the repository
1. Configure and install the dependencies: `pip3 install -r requirements.txt`
1. Create a new branch: `git checkout -b my-branch-name`
1. Push to your fork and submit a pull request
1. Pat your self on the back and wait for your pull request to be reviewed! :tada:

Here are a few things you can do that will increase the likelihood of your pull request being accepted:

- Follow the [style guide](https://black.readthedocs.io/en/stable/) - it'll automatically run via the [super-linter](https://github.com/github/super-linter).
- Write tests.
- Keep your change as focused as possible. If there are multiple changes you would like to make that are not dependent upon each other, consider submitting them as separate pull requests.
- Write a [good commit message](http://tbaggery.com/2008/04/19/a-note-about-git-commit-messages.html).

## Resources

- [How to Contribute to Open Source](https://opensource.guide/how-to-contribute/)
- [Using Pull Requests](https://help.github.com/articles/about-pull-requests/)
- [GitHub Help](https://help.github.com) IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE. # gh-org-admin-promote

GitHub CLI extension to promote an enterprise admin to an organization admin for all orgs in the enterprise. This is an API-first replacement of `ghe-org-admin-promote` on GitHub Enterprise Server. It also outputs an inventory of all organizations in the enterprise as a CSV file.

Should work on [all supported versions](https://docs.github.com/en/enterprise-server@latest/admin/all-releases#releases-of-github-enterprise-server) of GitHub Enterprise Server, as well as GitHub Enterprise Cloud.

## Permissions check

> [!IMPORTANT]
> This requires the `admin:enterprise` and `admin:org` scopes, which are only available to enterprise owners and not default for logging in to the gh cli.

Run `ghe auth status` to check your permissions. You should see `admin:enterprise` and `admin:org` in the list of scopes.

```console
$ gh auth status

ghes-test-instance.com
  ✓ Logged in to ghes-test-instance.com account some-natalie (keyring)
  - Active account: true
  - Git operations protocol: https
  - Token: gho_************************************
  - Token scopes: 'admin:enterprise', 'admin:org', 'gist', 'repo', 'workflow'
```

If you don't, do the following to add the right scopes:

```console
gh auth refresh -s admin:enterprise -s admin:org -h ghes-test-instance.com
```

## Installation

```console
gh extension install some-natalie/gh-org-admin-promote
```

## Usage

```console
$ export GH_HOST=ghes-test-instance.com # option for GHES, defaults to github.com

$ gh org-admin-promote enterprise-name

Getting total count of organizations in github...
Total count of organizations in github: 4
Getting list of organizations in github...
Promoting user to admin for testorg-00002...
User promoted to admin for testorg-00002
Promoting user to admin for testorg-00003...
User promoted to admin for testorg-00003
```

## Limitations

This will promote you to own all organizations, but it will not capture anything in a user-namespaced repository (e.g. `some-natalie/gh-org-admin-promote`). If you need reporting on all of these, for GHES, use the [all_repositories.csv report](https://docs.github.com/en/enterprise-server@latest/admin/administering-your-instance/administering-your-instance-from-the-web-ui/site-admin-dashboard#reports) to get a list.

# Security Policy

## Supported Versions

Only the latest major semver will receive security attention.

## Reporting a Vulnerability

Please open an issue with all information you can provide and add the "security" label.

# Support

## How to file issues and get help

This project uses GitHub issues to track bugs and feature requests. Please search the existing issues before filing new issues to avoid duplicates. For new issues, file your bug or feature request as a new issue.

For help or questions about using this project, please search the existing discussions and issues, then open a new discussion. Thanks!

**gh-org-admin-promote** is actively developed and is maintained by GitHub staff **AND THE COMMUNITY** on a best-effort basis. We will do our best to respond to support and community questions in a timely manner.

## GitHub Support Policy

Support for this project is limited to the resources listed above.

module github.com/some-natalie/gh-org-admin-promote

go 1.21.5

require (
	github.com/cli/go-gh/v2 v2.4.0
	github.com/cli/shurcooL-graphql v0.0.4
)

require (
	github.com/aymanbagabas/go-osc52/v2 v2.0.1 // indirect
	github.com/cli/safeexec v1.0.1 // indirect
	github.com/henvic/httpretty v0.1.3 // indirect
	github.com/kr/text v0.2.0 // indirect
	github.com/lucasb-eyer/go-colorful v1.2.0 // indirect
	github.com/mattn/go-isatty v0.0.20 // indirect
	github.com/mattn/go-runewidth v0.0.15 // indirect
	github.com/muesli/termenv v0.15.2 // indirect
	github.com/rivo/uniseg v0.4.4 // indirect
	github.com/stretchr/testify v1.8.1 // indirect
	github.com/thlib/go-timezone-local v0.0.0-20210907160436-ef149e42d28e // indirect
	golang.org/x/sys v0.15.0 // indirect
	golang.org/x/term v0.15.0 // indirect
	golang.org/x/text v0.14.0 // indirect
	gopkg.in/yaml.v3 v3.0.1 // indirect
)

/*
Copyright © 2023 Natalie Somersall
*/
package main

import (
	"encoding/csv"
	"fmt"
	"log"
	"os" h1:5Nx0Ya0ZqY2ygV366QzturHI13Jq95ApcVaJBhpS+AY= h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4= h1:BuzhfgfWQbX0dWzYzT1zsORLnHRv3bcRcsaUk0VmXA8= +gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= "github.com/cli/go-gh/v2/pkg/api"
	graphql "github.com/cli/shurcooL-graphql"
)

func main() {
	// -h flag or no arguments provided
	if len(os.Args) < 1 || os.Args[1] == "-h" {
		fmt.Println("Usage: gh org-admin-promote GITHUB_ENTERPRISE_SLUG")
		fmt.Println("Promotes the authenticated user to admin for all organizations in the specified enterprise")
		fmt.Println("GH_TOKEN requires the following scopes: admin:enterprise, admin:org")
		fmt.Println("See https://cli.github.com/manual/gh_auth_login to add scopes to gh cli!")
		os.Exit(0)
	}

	// Get the enterprise slug from args
	enterpriseSlug := os.Args[1]

	// Get the hostname from the environment variable, otherwise default to github.com
	hostname := os.Getenv("GH_HOST")
	if hostname == "" {
		hostname = "github.com"
	}

	// Create a GraphQL client using the hostname from the gh cli
	opts := api.ClientOptions{
		Host: hostname,
	}
	client, err := api.NewGraphQLClient(opts)
	if err != nil {
		log.Fatal(err)
	} // Get the enterprise ID from the enterprise slug
	var enterpriseIDQuery struct {
		Enterprise struct {
			ID string `graphql:"id"`
		} `graphql:"enterprise(slug: $slug)"`
	}
	variables := map[string]interface{}{
		"slug": graphql.String(enterpriseSlug),
	}
	err = client.Query("EnterpriseID", &enterpriseIDQuery, variables)
	if err != nil {
		log.Fatal(err)
	}
	enterpriseID := enterpriseIDQuery.Enterprise.ID

	// Get a total count of organizations in the enterprise
	var orgCountQuery struct {
		Enterprise struct {
			Organizations struct {
				TotalCount int `graphql:"totalCount"`
			} `graphql:"organizations"`
		} `graphql:"enterprise(slug: $slug)"`
	}
	fmt.Printf("Getting total count of organizations in %s...\n", enterpriseSlug)
	variables = map[string]interface{}{
		"slug": graphql.String(enterpriseSlug),
	}
	err = client.Query("OrgCount", &orgCountQuery, variables)
	if err != nil {
		log.Fatal(err)
	}
	orgCount := orgCountQuery.Enterprise.Organizations.TotalCount fmt.Printf("Total count of organizations in %s: %d\n", enterpriseSlug, orgCount)

	// Create a CSV file
	csvFile, err := os.Create("all_orgs.csv")
	if err != nil {
		log.Fatal(err)
	}
	defer csvFile.Close()

	writer := csv.NewWriter(csvFile)
	defer writer.Flush()

	// Write CSV header
	err = writer.Write([]string{"ID", "CreatedAt", "Login", "Email", "ViewerCanAdminister", "ViewerIsAMember", "Repo_TotalCount", "Repo_TotalDiskUsage"})
	if err != nil {
		log.Fatal(err)
	}

	// Get a list of organizations in the enterprise
	var orgListQuery struct {
		Enterprise struct {
			Organizations struct {
				Edges []struct {
					Node struct {
						ID                  string `graphql:"id"`
						CreatedAt           string `graphql:"createdAt"`
						Login               string `graphql:"login"`
						Email               string `graphql:"email"`
						ViewerCanAdminister bool   `graphql:"viewerCanAdminister"`
						ViewerIsAMember     bool   `graphql:"viewerIsAMember"`
						Repositories struct {
							TotalCount     int `graphql:"totalCount"`
							TotalDiskUsage int `graphql:"totalDiskUsage"`
						} `graphql:"repositories"`
					} `graphql:"node"`
				} `graphql:"edges"`
				PageInfo struct {
					EndCursor   string `graphql:"endCursor"`
					HasNextPage bool   `graphql:"hasNextPage"`
				}
			} `graphql:"organizations(first: 100, after: $cursor)"`
		} `graphql:"enterprise(slug: $slug)"`
	}
	fmt.Printf("Getting list of organizations in %s...\n", enterpriseSlug)
	variables = map[string]interface{}{
		"slug":   graphql.String(enterpriseSlug),
		"cursor": (*graphql.String)(nil),
	}
	page := 1
	for {
		if err := client.Query("OrgList", &orgListQuery, variables); err != nil {
			log.Fatal(err)
		}

		// Write each organization to the CSV file
		for _, org := range orgListQuery.Enterprise.Organizations.Edges {
			err = writer.Write([]string{org.Node.ID, org.Node.CreatedAt, org.Node.Login, org.Node.Email, fmt.Sprintf("%t", org.Node.ViewerCanAdminister), fmt.Sprintf("%t", org.Node.ViewerIsAM org.Node.Repositories.TotalDiskUsage)}) + if err != nil { + log.Fatal(err) + } + } + + // Promote this user to enterprise admin for all organizations where ViewerCanAdminister is false + for _, org := range orgListQuery.Enterprise.Organizations.Edges { + if !org.Node.ViewerCanAdminister { + fmt.Printf("Promoting user to admin for %s...\n", org.Node.Login) + var promoteAdmin struct { + UpdateEnterpriseOwnerOrganizationRole struct { + ClientMutationId string + } `graphql:"updateEnterpriseOwnerOrganizationRole(input: $input)"` + } + + type UpdateEnterpriseOwnerOrganizationRoleInput struct { + EnterpriseId graphql.ID `json:"enterpriseId"` + OrganizationId graphql.ID `json:"organizationId"` + OrganizationRole graphql.String `json:"organizationRole"` + } + + variables := map[string]interface{}{ + "input": UpdateEnterpriseOwnerOrganizationRoleInput{ + EnterpriseId: graphql.ID(enterpriseID), + OrganizationId: graphql.ID(org.Node.ID), + OrganizationRole: graphql.String("OWNER"), + }, + } + + err = client.Mutate("PromoteAdmin", &promoteAdmin, variables) + if err != nil { + log.Fatal(err) + } + fmt.Printf("User promoted to admin for %s\n", org.Node.Login) + } + } + + // If there are no more pages, break out of the loop + if !orgListQuery.Enterprise.Organizations.PageInfo.HasNextPage { + break + } + + // Otherwise, update the cursor and page number + variables["cursor"] = graphql.String(orgListQuery.Enterprise.Organizations.PageInfo.EndCursor) + page++ + } + + // Close the CSV file + csvFile.Close() + +}