Skip to content

Suggested test: copilot/hosted-web-unsupported-engine #18366

Description

@github-actions

Motivation

Link to the gh-aw PR: github/gh-aw#63212 — Adds network.hosted-web frontmatter policy (deny-by-default) so provider-hosted Claude/Codex web tools have an explicit, separate domain allowlist from network.allowed, since those hosted tools execute outside AWF's network boundary. Existing open suggestions #18153 and #17932 already cover Claude and Codex variants of this feature; Copilot is not one of the supported engines for hosted-web per the PR (Claude/Codex only), so this issue instead proposes a compiler-rejection test to confirm that boundary is enforced.

Proposed test

  • Workflow file: test-copilot-hosted-web-unsupported-engine-rejection.md
  • Trigger: workflow_dispatch
  • Engine: copilot
  • Safe output: none required — compile-time validation test
  • Variant: standard

Minimal test prompt sketch

Author a workflow with engine: copilot and a network.hosted-web block (e.g. enabled: true, allowed: [docs.github.com]). Assert via gh aw compile that compilation fails (or is ignored/warned) because hosted-web is only meaningful for Claude/Codex engines whose web tools run outside the firewall boundary.

New fixtures or secrets needed

None.

Notes

This is complementary to, not a duplicate of, #18153 (claude/hosted-web-domain-policy) and #17932 (codex/hosted-web-domain-policy), which test the happy-path policy compilation for the supported engines. This issue instead closes the gap on the negative/unsupported-engine case. If gh-aw's actual behavior is to silently ignore hosted-web for Copilot rather than reject it, the test should assert that instead — worth confirming compiler behavior before implementing.

Generated by 🔍 Suggest New E2E Tests · copilot · auto · 65.1 AIC · ⌖ 9.43 AIC · ⊞ 8.5K · ◷

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions