Skip to content

codex: verify review collaborators independently - #31

Closed
ttaylorr-oai wants to merge 1 commit into
metafrom
ttaylorr/codex-review-permission-fix-bot
Closed

codex: verify review collaborators independently#31
ttaylorr-oai wants to merge 1 commit into
metafrom
ttaylorr/codex-review-permission-fix-bot

Conversation

@ttaylorr-oai

Copy link
Copy Markdown
Collaborator

The plan admission runner can see an organization-member approval as author_association=NONE when it uses GITHUB_TOKEN. Keep the exact-head and latest-review checks, then fall back to the repository collaborator endpoint before rejecting the reviewer. A missing collaborator or API failure still fails closed.

This unblocks the trusted admission path for PR #29 without weakening the review gate.

Tests:

  • sh -n .github/workflows/codex-branch.sh
  • git diff --check
  • targeted t9905 topic-review test: passed
  • full t9905: 116/117 passed; existing test 116 fails because current meta does not contain codex.release-recovery

The plan admission runner reads pull-request reviews with GITHUB_TOKEN. For organization members, GitHub can report author_association=NONE to that token even though a user token sees MEMBER. That makes a valid exact-head approval fail closed and blocks plan admission.

Keep the exact-head and latest-review checks, but fall back to the repository collaborator endpoint when the association is not already trusted. The endpoint is repository-scoped and available with metadata:read; a 404 or API failure still rejects the review.

Cover both the hidden-member success case and outsider rejection.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant