Repository navigation
ci(rescue): mint the read token with only the permissions the App has - #14627
Conversation
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
All contributors have signed the CLA ✍️ ✅ |
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (3)
💤 Files with no reviewable changes (1)
Included review availability: Your plan provides up to 10 included reviews per hour; 2 remain after this review. 📝 WalkthroughWalkthroughThe rescue script now retries a read with ChangesOwned pool rescue token handling
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Sequence Diagram(s)sequenceDiagram
participant GitHubRequest
participant GitHubAPI
participant AppToken
participant GITHUB_TOKEN
GitHubRequest->>GitHubAPI: Read using AppToken
GitHubAPI-->>GitHubRequest: Return 403
GitHubRequest->>GitHubAPI: Retry current read using GITHUB_TOKEN
GitHubRequest->>GitHubAPI: Send next read using AppToken
Merge Risk: ⚪ Minimal · up to The App token no longer requests the unavailable contents permission, and the workflow’s contents-enabled job token handles the branch lookup fallback. The 403 retry is limited to that request; no concrete merge-blocking regression is evident. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change narrows the requested App permissions and keeps denied-read retries within the existing rescue workflow. No new security finding was established, but token fallback warrants review because it changes which credential makes a read. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 24 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (24 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Merge receipt for |
bd2d34e test: expect split zoom to survive closing one tab of a zoomed pane (manaflow-ai#14664) f8857c5 fix(scripts): append, not prepend, the cargo fallback PATH in build-cmux-cua.sh (manaflow-ai#14665) 56a3e4c fix: make the event-stream reconnect decision a value, not a static namespace (manaflow-ai#14661) 06e064d ci: pin cla.yml and claude.yml to a GitHub-hosted runner (manaflow-ai#14668) 2509187 ci: restore the git object seed before checkout in E2E and iOS macOS jobs (manaflow-ai#14669) 402d0ad docs: move team-internal fleet and session rules out of CLAUDE.md (manaflow-ai#14595) 3bfe0b6 pull_request_template: drop the commented @codex review trigger block (manaflow-ai#14599) 4f0ac55 fix(control): honor color/icon keys and validate hex in workspace.group.set_color/set_icon (manaflow-ai#13877) 805a699 ci(rescue): mint the read token with only the permissions the App has (manaflow-ai#14627) 7e662c0 Tell the user why a file upload failed (manaflow-ai#11476) f04320e test: yield to the main queue while the Files tree catches up after its menu closes (manaflow-ai#14660) a5f705b A mirrored tmux window with one pane shows two tab bars (manaflow-ai#11248) 74917a9 iOS: remove unshipped push reconnect banner # Conflicts: # .github/workflows/ci-owned-pool-rescue.yml # .github/workflows/cla.yml # .github/workflows/claude.yml # .github/workflows/test-e2e.yml # .github/workflows/test-ios.yml
#14499 moved the owned-pool watch's reads to a manaflow-glaeda-route App token, but every mint since then has failed:
The step asks for
contents: read, and the installation has no contents grant (hq#639 lists actions, pull_requests and administration). The step is continue-on-error, so the watch kept working but read on GITHUB_TOKEN, and the move saved nothing. Example: run 36138293052.Changes
actions: readandpull-requests: read.owned_pool_rescue.pyonly reads/actions/*and/pulls/{n}.Tokens.test_a_read_the_app_may_not_make_uses_github_token_once. The mint-permissions test is updated. 94 tests pass, and actionlint is clean.🤖 Generated with Claude Code
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Fixes the rescue watch's App token mint, which was failing with 422 because it asked for a
contents: readpermission the installation doesn't have.actions: readandpull-requests: read, matching the endpointsowned_pool_rescue.pyreads.GITHUB_TOKEN; a 401 (expired token) still switches all later reads back toGITHUB_TOKENfor the rest of the watch.branch_headon/branches) is the fallback that triggers.Written for commit 935a947. Summary will update on new commits.
Summary by CodeRabbit