Repository navigation
ci: enforce protected-path exclusions with --disallowedTools - #260
Conversation
WalkthroughThree GitHub Actions workflows update Claude tool permissions, adding protected-path deny rules and adjusting comments around ChangesClaude workflow tool policy updates
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related issues
Possibly related PRs
Suggested labels: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Preview DeploymentPreview URL: https://aed3e7c5.bestax.pages.dev |
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/bestaxbot-reply.yml:
- Around line 158-164: The Claude tool allowlist in bestaxbot-reply workflow is
too broad because Edit and Write are granted across the whole workspace, so the
prompt-only path exclusions are not enforced. Update the `claude_args` block to
scope `Edit`/`Write` to the intended paths or add explicit `--disallowedTools`
restrictions for the excluded files, keeping the change centered on the
`claude_args` configuration.
In @.github/workflows/claude-implement.yml:
- Around line 110-116: The current claude_args allowlist grants repo-wide Edit
and Write access, so the prompt-only “never touch” restriction is not enforced.
Update the workflow’s claude_args in claude-implement.yml to scope Edit/Write
through tool-policy or path-specific rules, and explicitly constrain them to the
intended config areas such as .github/**, Jest/commitlint/release configs,
pnpm-workspace.yaml, .npmrc, .coderabbit.yaml, and turbo.json.
In @.github/workflows/claude-pr-loop.yml:
- Around line 367-373: The fix-agent allowlist in the claude_args block still
grants Edit and Write access, which leaves the workflow vulnerable to
prompt-injected repo edits. Remove Edit and Write from the allowedTools list in
the claude_args configuration, keeping the step read-only unless a later stage
explicitly requires write access; use the claude_args block as the place to
update the tool permissions.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro Plus
Run ID: e7ef8525-b044-4f76-b69b-8f7493cd06ed
📒 Files selected for processing (3)
.github/workflows/bestaxbot-reply.yml.github/workflows/claude-implement.yml.github/workflows/claude-pr-loop.yml
The agent prompts forbid touching .github/**, pnpm-workspace.yaml, .npmrc, .coderabbit.yaml, turbo.json, and the jest/commitlint/release configs, but prompt text is advisory - with a bare Edit,Write allow the whole workspace was writable. Mirror the exclusion list as --disallowedTools deny rules, which take precedence over allow rules, so the limits are enforced by the permission layer rather than prose. Addresses the CodeRabbit review on #260.
The agent prompts forbid touching .github/**, pnpm-workspace.yaml, .npmrc, .coderabbit.yaml, turbo.json, and the jest/commitlint/release configs, but prompt text is advisory - the bare Edit/MultiEdit/Write grant from #258 makes the whole workspace writable. Mirror the exclusion list as --disallowedTools deny rules, which take precedence over allow rules, so the limits are enforced by the permission layer rather than prose. Raised by the CodeRabbit review on #260.
6114295 to
4669969
Compare
Preview DeploymentPreview URL: https://4234b20e.bestax.pages.dev |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/bestaxbot-reply.yml:
- Around line 164-165: The tool allowlist in the workflow still leaves a write
path open through Bash(sed:*), which can bypass the protected-path restrictions
enforced by the disallowed Edit/MultiEdit/Write entries. Update the allowedTools
configuration to remove or tightly scope the sed Bash allowance so protected
files cannot be modified via sed -i. Keep the restriction aligned with the
existing tool policy in bestaxbot-reply.yml.
In @.github/workflows/claude-pr-loop.yml:
- Around line 373-374: The Bash allowlist in the workflow still permits
write-capable sed usage through the generic Bash(sed:*) entry, which can bypass
the protected-path restrictions. Update the allowedTools list to restrict sed to
read-only usage (for example, a narrowed matcher like Bash(sed -n:*) or remove
sed entirely) so only non-mutating commands are permitted alongside the existing
Edit/MultiEdit/Write blocks.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro Plus
Run ID: c2b16cca-a04a-47e8-be48-bd80c6a4297f
📒 Files selected for processing (3)
.github/workflows/bestaxbot-reply.yml.github/workflows/claude-implement.yml.github/workflows/claude-pr-loop.yml
🚧 Files skipped from review as they are similar to previous changes (1)
- .github/workflows/claude-implement.yml
|
🎉 This PR is included in version 3.2.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
|
🎉 This PR is included in version 1.0.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
|
🎉 This PR is included in version 1.0.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
Summary
Follow-up hardening to #258 (which allowlisted
Edit/MultiEdit/Writefor the three write-capable agents — superseding this PR's original first commit, since both made the same change).The agent prompts forbid touching
.github/**,pnpm-workspace.yaml,.npmrc,.coderabbit.yaml,turbo.json, and the jest/commitlint/release configs — but prompt text is advisory, and with the bare file-tool grant now on main the whole workspace is writable. CodeRabbit flagged this on the original revision of this PR (3× Major: "the prompt-only exclusions don't enforce anything").This PR mirrors the exclusion list as
--disallowedToolsdeny rules in the same three workflows (bestaxbot-reply.yml,claude-pr-loop.ymlfix step,claude-implement.yml). Deny rules take precedence over allow rules, so the protected paths are enforced by the permission layer rather than prose:Known residual gap (accepted):
Bash(sed:*)/Bash(node:*)remain allowlisted and could still write protected files; removing them would break how the agents work today. The loop's changed-files gate (halting on.github/**etc.) stays as the backstop.Closes #259 (core defect fixed by #258; this carries the enforcement remainder).
Test plan
--disallowedToolsline + explanatory comment in each of the three filesbestaxbot-replyon a bestaxbot PR (e.g. feat(bulma-ui): add Avatar, Avatars, and Badge components #257) — file edits inside package dirs succeed; an attempted edit of a protected path is denied in the logSummary by CodeRabbit
Edit/MultiEdit/Writechanges under protected paths (including.github/**and key repo config/test/release files), with deny precedence over existing allowlists.