mirror of
https://github.com/anthropics/claude-code-action.git
synced 2026-08-22 03:18:54 +08:00
fix: handle non-user actors (e.g. Copilot) in permission and actor checks (#1144)
GitHub Apps like Copilot SWE Agent set GITHUB_ACTOR to a value (e.g. "Copilot") that is neither a valid GitHub user nor ends with "[bot]". This caused two independent crashes: 1. checkWritePermissions (permissions.ts): called the collaborator permission API which returns 404 "is not a user" for non-user actors. 2. checkHumanActor (actor.ts): called the Users API first, which 404s, before ever reaching the allowed_bots check. Fix both by: - Checking allowed_bots BEFORE making API calls, so known bots skip the API entirely. - In permissions.ts, catching "is not a user" 404 errors and falling back to the allowed_bots list instead of crashing. - In actor.ts, catching 404 errors and providing a clear error message telling the user to add the bot to allowed_bots. Closes #900, #903, #1018, #1133 Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -93,4 +93,78 @@ describe("checkHumanActor", () => {
|
||||
"Workflow initiated by non-human actor: other-bot (type: Bot). Add bot to allowed_bots list or use '*' to allow all bots.",
|
||||
);
|
||||
});
|
||||
|
||||
describe("non-[bot] actors (e.g. GitHub Copilot)", () => {
|
||||
// GitHub Copilot SWE Agent sets GITHUB_ACTOR="Copilot" which is not a
|
||||
// valid GitHub user and doesn't end with [bot], causing 404 on the
|
||||
// Users API. These tests verify the fix handles this gracefully.
|
||||
|
||||
function createMockOctokitThat404s(): Octokit {
|
||||
return {
|
||||
users: {
|
||||
getByUsername: async () => {
|
||||
const err = new Error("Not Found");
|
||||
(err as any).status = 404;
|
||||
throw err;
|
||||
},
|
||||
},
|
||||
} as unknown as Octokit;
|
||||
}
|
||||
|
||||
test("should pass for non-[bot] actor when in allowed_bots list", async () => {
|
||||
const mockOctokit = createMockOctokitThat404s();
|
||||
const context = createMockContext();
|
||||
context.actor = "Copilot";
|
||||
context.inputs.allowedBots = "copilot,cursor";
|
||||
|
||||
// Should not even call the API — allowed_bots check happens first
|
||||
await expect(
|
||||
checkHumanActor(mockOctokit, context),
|
||||
).resolves.toBeUndefined();
|
||||
});
|
||||
|
||||
test("should pass for non-[bot] actor when all bots are allowed", async () => {
|
||||
const mockOctokit = createMockOctokitThat404s();
|
||||
const context = createMockContext();
|
||||
context.actor = "Copilot";
|
||||
context.inputs.allowedBots = "*";
|
||||
|
||||
await expect(
|
||||
checkHumanActor(mockOctokit, context),
|
||||
).resolves.toBeUndefined();
|
||||
});
|
||||
|
||||
test("should throw with clear message for non-[bot] actor that 404s and is not in allowed list", async () => {
|
||||
const mockOctokit = createMockOctokitThat404s();
|
||||
const context = createMockContext();
|
||||
context.actor = "Copilot";
|
||||
context.inputs.allowedBots = "cursor";
|
||||
|
||||
await expect(checkHumanActor(mockOctokit, context)).rejects.toThrow(
|
||||
"Workflow initiated by non-human actor: copilot (actor not found on GitHub). Add bot to allowed_bots list or use '*' to allow all bots.",
|
||||
);
|
||||
});
|
||||
|
||||
test("should throw with clear message for non-[bot] actor that 404s and allowed_bots is empty", async () => {
|
||||
const mockOctokit = createMockOctokitThat404s();
|
||||
const context = createMockContext();
|
||||
context.actor = "Copilot";
|
||||
context.inputs.allowedBots = "";
|
||||
|
||||
await expect(checkHumanActor(mockOctokit, context)).rejects.toThrow(
|
||||
"Workflow initiated by non-human actor: copilot (actor not found on GitHub). Add bot to allowed_bots list or use '*' to allow all bots.",
|
||||
);
|
||||
});
|
||||
|
||||
test("should match allowed_bots case-insensitively for non-[bot] actors", async () => {
|
||||
const mockOctokit = createMockOctokitThat404s();
|
||||
const context = createMockContext();
|
||||
context.actor = "Copilot";
|
||||
context.inputs.allowedBots = "COPILOT";
|
||||
|
||||
await expect(
|
||||
checkHumanActor(mockOctokit, context),
|
||||
).resolves.toBeUndefined();
|
||||
});
|
||||
});
|
||||
});
|
||||
|
||||
@@ -303,4 +303,104 @@ describe("checkWritePermissions", () => {
|
||||
);
|
||||
});
|
||||
});
|
||||
|
||||
describe("non-[bot] actors (e.g. GitHub Copilot)", () => {
|
||||
// GitHub Copilot SWE Agent sets GITHUB_ACTOR="Copilot" which doesn't
|
||||
// end with [bot] and is not a valid GitHub user, so the collaborator
|
||||
// permission API returns 404 with "is not a user".
|
||||
|
||||
const createMockOctokitThat404s = () => ({
|
||||
repos: {
|
||||
getCollaboratorPermissionLevel: async () => {
|
||||
const err = new Error(
|
||||
"HttpError: Copilot is not a user - https://docs.github.com/rest/collaborators/collaborators#get-repository-permissions-for-a-user",
|
||||
);
|
||||
(err as any).status = 404;
|
||||
throw err;
|
||||
},
|
||||
},
|
||||
} as any);
|
||||
|
||||
test("should return true for non-[bot] actor in allowed_bots (pre-API check)", async () => {
|
||||
// The allowed_bots check should happen BEFORE calling the API,
|
||||
// so this should succeed even with a 404-ing mock.
|
||||
const mockOctokit = createMockOctokitThat404s();
|
||||
const context = createContext();
|
||||
context.actor = "Copilot";
|
||||
context.inputs.allowedBots = "copilot,cursor";
|
||||
|
||||
const result = await checkWritePermissions(mockOctokit, context);
|
||||
|
||||
expect(result).toBe(true);
|
||||
expect(coreInfoSpy).toHaveBeenCalledWith(
|
||||
"Actor Copilot is in allowed_bots list, skipping permission check",
|
||||
);
|
||||
});
|
||||
|
||||
test("should return true for non-[bot] actor when allowed_bots is '*' (pre-API check)", async () => {
|
||||
const mockOctokit = createMockOctokitThat404s();
|
||||
const context = createContext();
|
||||
context.actor = "Copilot";
|
||||
context.inputs.allowedBots = "*";
|
||||
|
||||
const result = await checkWritePermissions(mockOctokit, context);
|
||||
|
||||
expect(result).toBe(true);
|
||||
});
|
||||
|
||||
test("should return true for non-[bot] actor in allowed_bots via 404 fallback", async () => {
|
||||
// Even if somehow we reach the API call (e.g. race condition or
|
||||
// future refactor), the 404 catch path should also check allowed_bots.
|
||||
const mockOctokit = createMockOctokitThat404s();
|
||||
const context = createContext();
|
||||
context.actor = "SomeNewBot";
|
||||
context.inputs.allowedBots = "somenewbot";
|
||||
|
||||
const result = await checkWritePermissions(mockOctokit, context);
|
||||
|
||||
expect(result).toBe(true);
|
||||
});
|
||||
|
||||
test("should return false for non-[bot] actor that 404s and is not in allowed_bots", async () => {
|
||||
const mockOctokit = createMockOctokitThat404s();
|
||||
const context = createContext();
|
||||
context.actor = "Copilot";
|
||||
context.inputs.allowedBots = "cursor";
|
||||
|
||||
const result = await checkWritePermissions(mockOctokit, context);
|
||||
|
||||
expect(result).toBe(false);
|
||||
expect(coreWarningSpy).toHaveBeenCalledWith(
|
||||
"Non-user actor Copilot is not in allowed_bots list. Add it to allowed_bots or use '*' to allow all bots.",
|
||||
);
|
||||
});
|
||||
|
||||
test("should return false for non-[bot] actor that 404s with empty allowed_bots", async () => {
|
||||
const mockOctokit = createMockOctokitThat404s();
|
||||
const context = createContext();
|
||||
context.actor = "Copilot";
|
||||
context.inputs.allowedBots = "";
|
||||
|
||||
const result = await checkWritePermissions(mockOctokit, context);
|
||||
|
||||
expect(result).toBe(false);
|
||||
});
|
||||
|
||||
test("should still throw for non-404 API errors", async () => {
|
||||
const mockOctokit = {
|
||||
repos: {
|
||||
getCollaboratorPermissionLevel: async () => {
|
||||
throw new Error("Internal Server Error");
|
||||
},
|
||||
},
|
||||
} as any;
|
||||
const context = createContext();
|
||||
context.actor = "Copilot";
|
||||
context.inputs.allowedBots = "";
|
||||
|
||||
await expect(checkWritePermissions(mockOctokit, context)).rejects.toThrow(
|
||||
"Failed to check permissions for Copilot",
|
||||
);
|
||||
});
|
||||
});
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user