feat(robomp): improved authorization and login normalization

- Implemented case-insensitive normalization for bot logins to handle mention handles and `[bot]` suffixes consistently.
- Added support for `ROBOMP_MAINTAINER_LOGINS` to allow authorized non-owner users to execute implementations.
- Refined authorization logic to distinguish between personal repository owners and organizational accounts.
- Updated documentation and added comprehensive tests to verify authorization handling across tasks, workers, and directive processing.
This commit is contained in:
can1357
2026-06-21 19:14:13 +02:00
parent 4b9f7cd8fa
commit 4b2e4085e0
11 changed files with 453 additions and 20 deletions
+4 -2
View File
@@ -129,7 +129,7 @@ class Settings(BaseSettings):
rate_limit_default: int = Field(3, alias="ROBOMP_RATE_LIMIT_DEFAULT")
rate_limit_contributor: int = Field(10, alias="ROBOMP_RATE_LIMIT_CONTRIBUTOR")
rate_limit_unlimited_raw: str = Field("", alias="ROBOMP_RATE_LIMIT_UNLIMITED")
# Logins (comma-separated, `@` prefix optional) whose `@bot_login`
# Logins (comma-separated, `@` prefix optional, case-insensitive) whose `@bot_login`
# mentions are treated as authoritative directives. These accounts also
# bypass rate limiting regardless of `author_association`.
maintainer_logins_raw: str = Field("", alias="ROBOMP_MAINTAINER_LOGINS")
@@ -163,7 +163,9 @@ class Settings(BaseSettings):
@field_validator("bot_login", mode="after")
@classmethod
def _require_bot_login(cls, value: str) -> str:
cleaned = value.strip().removeprefix("@")
cleaned = value.strip().removeprefix("@").lower()
if cleaned.endswith("[bot]"):
cleaned = cleaned[:-5]
if not cleaned:
raise ValueError("ROBOMP_BOT_LOGIN must be a non-empty GitHub login")
return cleaned