feat(python/robomp): implemented has_authorized_impl_event in the
- Implement `has_authorized_impl_event` in the database to retrieve historical authorization state. - Update `_enforce_impl_authorization` to permit actions if prior events on the issue provided implementation authorization. - Normalize maintainer logins by stripping `[bot]` suffixes and allow match-regex to ignore them.
This commit is contained in:
@@ -305,7 +305,10 @@ class Settings(BaseSettings):
|
||||
|
||||
@property
|
||||
def maintainer_logins(self) -> frozenset[str]:
|
||||
items = [piece.strip().lstrip("@").lower() for piece in self.maintainer_logins_raw.split(",")]
|
||||
items = [
|
||||
piece.strip().lstrip("@").lower().removesuffix("[bot]")
|
||||
for piece in self.maintainer_logins_raw.split(",")
|
||||
]
|
||||
return frozenset(item for item in items if item)
|
||||
|
||||
def allows(self, full_name: str) -> bool:
|
||||
|
||||
@@ -607,6 +607,26 @@ class Database:
|
||||
last_error=row["last_error"],
|
||||
)
|
||||
|
||||
def has_authorized_impl_event(self, issue_key: str) -> bool:
|
||||
"""Return whether a non-skipped event on this issue carried implementation authorization."""
|
||||
with self._lock:
|
||||
rows = self._conn.execute(
|
||||
"""
|
||||
SELECT payload_json
|
||||
FROM events
|
||||
WHERE issue_key = ?
|
||||
AND state <> 'skipped'
|
||||
ORDER BY received_at DESC
|
||||
""",
|
||||
(issue_key,),
|
||||
).fetchall()
|
||||
for row in rows:
|
||||
payload = json.loads(row["payload_json"])
|
||||
directive = payload.get("_robomp_directive")
|
||||
if isinstance(directive, dict) and directive.get("authorizes_impl") is True:
|
||||
return True
|
||||
return False
|
||||
|
||||
def requeue_event(
|
||||
self,
|
||||
delivery_id: str,
|
||||
|
||||
@@ -89,16 +89,11 @@ def _login_matches_personal_repo_owner(
|
||||
raw_type = owner.get("type")
|
||||
if isinstance(raw_type, str) and raw_type:
|
||||
owner_type = raw_type
|
||||
if owner_type is not None and owner_type.lower() == "organization":
|
||||
if owner_type is None or owner_type.lower() != "user":
|
||||
return False
|
||||
if owner_login:
|
||||
return login.lower() == owner_login.lower()
|
||||
if not isinstance(repo, str):
|
||||
if not owner_login:
|
||||
return False
|
||||
owner, sep, _name = repo.partition("/")
|
||||
if not sep or not owner:
|
||||
return False
|
||||
return login.lower() == owner.lower()
|
||||
return login.lower() == owner_login.lower()
|
||||
|
||||
|
||||
def _effective_association(
|
||||
@@ -158,7 +153,7 @@ def extract_mention(body: str | None, bot_login: str) -> str | None:
|
||||
if not login:
|
||||
return None
|
||||
pattern = re.compile(
|
||||
rf"(?<![A-Za-z0-9_-])@{re.escape(login)}(?![A-Za-z0-9_-])",
|
||||
rf"(?<![A-Za-z0-9_-])@{re.escape(login)}(?:\[bot\])?(?![A-Za-z0-9_-])",
|
||||
re.IGNORECASE,
|
||||
)
|
||||
if not pattern.search(body):
|
||||
|
||||
@@ -1121,6 +1121,8 @@ def _enforce_impl_authorization(
|
||||
"""Refuse first publish on issue classes that require maintainer authorization."""
|
||||
if bindings.impl_authorized:
|
||||
return
|
||||
if bindings.db.has_authorized_impl_event(bindings.issue_key):
|
||||
return
|
||||
row = bindings.db.get_issue(bindings.issue_key)
|
||||
if row is not None:
|
||||
if row.pr_number is not None:
|
||||
|
||||
Reference in New Issue
Block a user