feat(robomp): improved authorization and login normalization

- Implemented case-insensitive normalization for bot logins to handle mention handles and `[bot]` suffixes consistently.
- Added support for `ROBOMP_MAINTAINER_LOGINS` to allow authorized non-owner users to execute implementations.
- Refined authorization logic to distinguish between personal repository owners and organizational accounts.
- Updated documentation and added comprehensive tests to verify authorization handling across tasks, workers, and directive processing.
This commit is contained in:
can1357
2026-06-21 19:14:13 +02:00
parent 4b9f7cd8fa
commit 4b2e4085e0
11 changed files with 453 additions and 20 deletions
+26
View File
@@ -192,6 +192,32 @@ async def test_run_task_sets_impl_authorized_from_directive(
assert captured == {"impl_authorized": True}
@pytest.mark.asyncio
async def test_run_task_preserves_impl_authorized_when_resuming(
tmp_path: Path, settings: Settings, monkeypatch: pytest.MonkeyPatch
) -> None:
inputs, _bindings = _make_inputs(tmp_path, settings, session_has_jsonl=True)
captured: dict[str, bool] = {}
monkeypatch.setattr(worker, "_build_prompt", lambda *args, **kwargs: "prompt")
def capture_build(bindings: worker.ToolBindings) -> tuple:
captured["impl_authorized"] = bindings.impl_authorized
return ()
monkeypatch.setattr(worker.host_tools, "build", capture_build)
result = await worker.run_task(
task_kind="handle_comment",
inputs=inputs,
directive=worker.DirectiveInfo(body="go ahead", author="can1357", authorizes_impl=True),
)
assert result == "ok"
assert captured == {"impl_authorized": True}
assert _FakeRpcClient.instances[0].kwargs["extra_args"] == ("--continue",)
@pytest.mark.asyncio
async def test_run_rpc_passes_continue_when_session_jsonl_present(tmp_path: Path, settings: Settings) -> None:
inputs, bindings = _make_inputs(tmp_path, settings, session_has_jsonl=True)