不会。composer clear-cache仅清理~/.composer/cache/下的files/、repo/、vcs/子目录,而github令牌明文存储在~/.composer/auth.json的github-oauth字段中,不在缓存路径内。

composer clear-cache 会删掉 GitHub 令牌缓存吗?
不会。composer clear-cache 只清理 ~/.composer/cache/ 下的 files/、repo/、vcs/ 子目录,而 GitHub 令牌(如 github-oauth 配置)是明文存在全局配置文件 ~/.composer/auth.json 里的,完全不在缓存路径中。
GitHub 令牌实际存在哪?怎么确认是否过期?
令牌以 JSON 格式写在 ~/.composer/auth.json 的 github-oauth 字段下。过期表现不是报错“token expired”,而是:
• composer update 卡在 Cloning into '...' 或直接失败
• 出现 401 Unauthorized 或 403 rate limit exceeded(尤其在私有仓库或高频操作时)
• composer diagnose 显示 GitHub API is not working properly
检查方式:
• 运行 cat ~/.composer/auth.json 查看是否有 "github-oauth" 字段
• 手动用 curl -H "Authorization: token YOUR_TOKEN" https://api.github.com/user 测试返回状态
• 注意:GitHub 已弃用密码认证,且 Personal Access Token 必须带 repo(私有库)或 public_repo(公开库)权限
如何安全更新或删除旧的 GitHub 令牌?
别手动编辑 auth.json —— 容易格式错误导致后续所有 Composer 命令报 JSON decode error。用官方命令:
• 删除旧令牌:composer config --global --unset github-oauth.github.com
• 设置新令牌:composer config --global github-oauth.github.com YOUR_NEW_TOKEN
• 查看当前配置:composer config --global github-oauth.github.com(不加值就是只读)
注意点:
• --global 不可省略,否则改的是当前项目级配置(./auth.json)
• Windows 用户路径是 %APPDATA%\Composer\auth.json,命令一样有效
• 如果公司用自建 Git 服务(如 Gitea、GitLab),对应字段是 gitlab-oauth 或自定义域名键名,操作逻辑相同
为什么删了令牌后 composer install 还能走通?
因为 Composer 会 fallback 到其他凭据机制:
• SSH agent(如果 git@github.com 克隆用的是 SSH URL)
• 系统 keychain(macOS Keychain / Windows Credential Manager 存的 git 凭据)
• ~/.netrc(部分 CI 环境用)
这意味着:
• 单纯删 auth.json 里的 token 并不等于“断掉所有 GitHub 访问”
• 真正要阻断,得同时禁用 SSH key、清空系统凭据、删 .netrc
• 但多数人只需要更新 token,不用动其他层——这也是最干净的做法
auth.json,就以明文存在磁盘上。如果机器多人共用或走 CI 构建,这个文件必须设权限为 600(chmod 600 ~/.composer/auth.json),否则任意用户都能 cat 出来。











