feat(robomp): improved authorization and login normalization
- Implemented case-insensitive normalization for bot logins to handle mention handles and `[bot]` suffixes consistently. - Added support for `ROBOMP_MAINTAINER_LOGINS` to allow authorized non-owner users to execute implementations. - Refined authorization logic to distinguish between personal repository owners and organizational accounts. - Updated documentation and added comprehensive tests to verify authorization handling across tasks, workers, and directive processing.
This commit is contained in:
@@ -28,9 +28,10 @@
|
||||
# configured in the GitHub webhook UI / settings.
|
||||
GITHUB_WEBHOOK_SECRET=
|
||||
|
||||
# Login name of the bot account whose PAT is in GITHUB_TOKEN (or whichever
|
||||
# account the gh-proxy authenticates as). Used to skip webhook events authored
|
||||
# by the bot itself.
|
||||
# GitHub login handle for the bot account whose PAT is in GITHUB_TOKEN (or
|
||||
# whichever account the gh-proxy authenticates as). Prefer the lowercase bare
|
||||
# mention handle (`roboomp`, not `@roboomp` or `roboomp[bot]`); startup
|
||||
# normalizes common forms, including uppercase and surrounding whitespace.
|
||||
ROBOMP_BOT_LOGIN=
|
||||
|
||||
# Commit identity for branches the bot pushes. The email is what reviewers and
|
||||
@@ -44,6 +45,11 @@ ROBOMP_GIT_AUTHOR_EMAIL=
|
||||
# Comma-separated owner/repo entries the bot is allowed to act on.
|
||||
ROBOMP_REPO_ALLOWLIST=
|
||||
|
||||
# Optional comma-separated GitHub logins whose @ROBOMP_BOT_LOGIN comments may
|
||||
# authorize implementation work in addition to repo OWNER. `@` and case do not
|
||||
# matter; use the webhook actor login, not a display name.
|
||||
ROBOMP_MAINTAINER_LOGINS=
|
||||
|
||||
|
||||
# =============================================================================
|
||||
# ### gh-proxy mode (RECOMMENDED, default in docker compose) ###
|
||||
|
||||
Reference in New Issue
Block a user