mirror of
https://github.com/anthropics/claude-code-action.git
synced 2026-08-22 03:18:54 +08:00
* ci: skip Claude-backed test jobs on fork PRs Jobs that run the action against the Claude API authenticate via workload identity federation, which fork PRs cannot mint an OIDC token for, so they always failed on external contributions. Gate each such job on the PR head repo matching the base repo; push and workflow_dispatch runs are unaffected. No-Verification-Needed: CI workflow config only, exercised by Actions on the PR * test: pin the bare remote's initial branch in fetch-depth test The shallow-clone case created its bare remote with a plain git init, so HEAD pointed at whatever init.defaultBranch resolves to (master on CI) while the test only pushed main. git clone --depth=1 implies --single-branch, and with a dangling remote HEAD it produces an empty, non-shallow clone, so the is-shallow assertion failed on runners whose default branch is not main. No-Verification-Needed: test-only change
203 lines
7.3 KiB
YAML
203 lines
7.3 KiB
YAML
name: Test Settings Feature
|
|
|
|
on:
|
|
pull_request:
|
|
workflow_dispatch:
|
|
workflow_call:
|
|
|
|
# The Claude API is authenticated via workload identity federation: id-token
|
|
# lets the action mint the GitHub OIDC token it exchanges for a short-lived
|
|
# access token. See docs/setup.md.
|
|
permissions:
|
|
contents: read
|
|
id-token: write
|
|
|
|
jobs:
|
|
test-settings-inline-allow:
|
|
# Skip on fork PRs since they can't mint the OIDC token used for Claude API auth
|
|
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
|
|
- name: Test with inline settings JSON (echo allowed)
|
|
id: inline-settings-test
|
|
uses: ./base-action
|
|
with:
|
|
prompt: |
|
|
Use Bash to echo "Hello from settings test"
|
|
anthropic_federation_rule_id: ${{ vars.ANTHROPIC_FEDERATION_RULE_ID }}
|
|
anthropic_organization_id: ${{ vars.ANTHROPIC_ORGANIZATION_ID }}
|
|
anthropic_service_account_id: ${{ vars.ANTHROPIC_SERVICE_ACCOUNT_ID }}
|
|
settings: |
|
|
{
|
|
"permissions": {
|
|
"allow": ["Bash(echo:*)"]
|
|
}
|
|
}
|
|
|
|
- name: Verify echo worked
|
|
run: |
|
|
OUTPUT_FILE="${{ steps.inline-settings-test.outputs.execution_file }}"
|
|
CONCLUSION="${{ steps.inline-settings-test.outputs.conclusion }}"
|
|
|
|
echo "Conclusion: $CONCLUSION"
|
|
|
|
if [ "$CONCLUSION" = "success" ]; then
|
|
echo "✅ Action completed successfully"
|
|
else
|
|
echo "❌ Action failed"
|
|
exit 1
|
|
fi
|
|
|
|
# Check that permission was NOT denied
|
|
if grep -q "Permission to use Bash with command echo.*has been denied" "$OUTPUT_FILE"; then
|
|
echo "❌ Echo command was denied when it should have been allowed"
|
|
cat "$OUTPUT_FILE"
|
|
exit 1
|
|
fi
|
|
|
|
# Check if the echo command worked
|
|
if grep -q "Hello from settings test" "$OUTPUT_FILE"; then
|
|
echo "✅ Bash echo command worked (allowed by permissions)"
|
|
else
|
|
echo "❌ Bash echo command didn't work"
|
|
cat "$OUTPUT_FILE"
|
|
exit 1
|
|
fi
|
|
|
|
test-settings-inline-deny:
|
|
# Skip on fork PRs since they can't mint the OIDC token used for Claude API auth
|
|
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
|
|
- name: Test with inline settings JSON (echo denied)
|
|
id: inline-settings-test
|
|
uses: ./base-action
|
|
with:
|
|
prompt: |
|
|
Run the command `echo $HOME` to check the home directory path
|
|
anthropic_federation_rule_id: ${{ vars.ANTHROPIC_FEDERATION_RULE_ID }}
|
|
anthropic_organization_id: ${{ vars.ANTHROPIC_ORGANIZATION_ID }}
|
|
anthropic_service_account_id: ${{ vars.ANTHROPIC_SERVICE_ACCOUNT_ID }}
|
|
settings: |
|
|
{
|
|
"permissions": {
|
|
"deny": ["Bash(echo:*)"]
|
|
}
|
|
}
|
|
|
|
- name: Verify echo was denied
|
|
run: |
|
|
OUTPUT_FILE="${{ steps.inline-settings-test.outputs.execution_file }}"
|
|
|
|
# Check that permission was denied in the tool_result
|
|
if grep -q "Permission to use Bash with command echo.*has been denied" "$OUTPUT_FILE"; then
|
|
echo "✅ Echo command was correctly denied by permissions"
|
|
else
|
|
echo "❌ Expected permission denied message not found"
|
|
cat "$OUTPUT_FILE"
|
|
exit 1
|
|
fi
|
|
|
|
test-settings-file-allow:
|
|
# Skip on fork PRs since they can't mint the OIDC token used for Claude API auth
|
|
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
|
|
- name: Create settings file (echo allowed)
|
|
run: |
|
|
cat > test-settings.json << EOF
|
|
{
|
|
"permissions": {
|
|
"allow": ["Bash(echo:*)"]
|
|
}
|
|
}
|
|
EOF
|
|
|
|
- name: Test with settings file
|
|
id: file-settings-test
|
|
uses: ./base-action
|
|
with:
|
|
prompt: |
|
|
Use Bash to echo "Hello from settings file test"
|
|
anthropic_federation_rule_id: ${{ vars.ANTHROPIC_FEDERATION_RULE_ID }}
|
|
anthropic_organization_id: ${{ vars.ANTHROPIC_ORGANIZATION_ID }}
|
|
anthropic_service_account_id: ${{ vars.ANTHROPIC_SERVICE_ACCOUNT_ID }}
|
|
settings: "test-settings.json"
|
|
|
|
- name: Verify echo worked
|
|
run: |
|
|
OUTPUT_FILE="${{ steps.file-settings-test.outputs.execution_file }}"
|
|
CONCLUSION="${{ steps.file-settings-test.outputs.conclusion }}"
|
|
|
|
echo "Conclusion: $CONCLUSION"
|
|
|
|
if [ "$CONCLUSION" = "success" ]; then
|
|
echo "✅ Action completed successfully"
|
|
else
|
|
echo "❌ Action failed"
|
|
exit 1
|
|
fi
|
|
|
|
# Check that permission was NOT denied
|
|
if grep -q "Permission to use Bash with command echo.*has been denied" "$OUTPUT_FILE"; then
|
|
echo "❌ Echo command was denied when it should have been allowed"
|
|
cat "$OUTPUT_FILE"
|
|
exit 1
|
|
fi
|
|
|
|
# Check if the echo command worked
|
|
if grep -q "Hello from settings file test" "$OUTPUT_FILE"; then
|
|
echo "✅ Bash echo command worked (allowed by permissions)"
|
|
else
|
|
echo "❌ Bash echo command didn't work"
|
|
cat "$OUTPUT_FILE"
|
|
exit 1
|
|
fi
|
|
|
|
test-settings-file-deny:
|
|
# Skip on fork PRs since they can't mint the OIDC token used for Claude API auth
|
|
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
|
|
- name: Create settings file (echo denied)
|
|
run: |
|
|
cat > test-settings.json << EOF
|
|
{
|
|
"permissions": {
|
|
"deny": ["Bash(echo:*)"]
|
|
}
|
|
}
|
|
EOF
|
|
|
|
- name: Test with settings file
|
|
id: file-settings-test
|
|
uses: ./base-action
|
|
with:
|
|
prompt: |
|
|
Run the command `echo $HOME` to check the home directory path
|
|
anthropic_federation_rule_id: ${{ vars.ANTHROPIC_FEDERATION_RULE_ID }}
|
|
anthropic_organization_id: ${{ vars.ANTHROPIC_ORGANIZATION_ID }}
|
|
anthropic_service_account_id: ${{ vars.ANTHROPIC_SERVICE_ACCOUNT_ID }}
|
|
settings: "test-settings.json"
|
|
|
|
- name: Verify echo was denied
|
|
run: |
|
|
OUTPUT_FILE="${{ steps.file-settings-test.outputs.execution_file }}"
|
|
|
|
# Check that permission was denied in the tool_result
|
|
if grep -q "Permission to use Bash with command echo.*has been denied" "$OUTPUT_FILE"; then
|
|
echo "✅ Echo command was correctly denied by permissions"
|
|
else
|
|
echo "❌ Expected permission denied message not found"
|
|
cat "$OUTPUT_FILE"
|
|
exit 1
|
|
fi
|