2026-06-27 22:08:45 -04:00
|
|
|
"""Helpers for resolving the triggering user's git identity."""
|
2026-03-25 13:39:33 -07:00
|
|
|
|
|
|
|
|
from __future__ import annotations
|
|
|
|
|
|
|
|
|
|
import logging
|
|
|
|
|
from dataclasses import dataclass
|
|
|
|
|
from typing import Any
|
|
|
|
|
|
|
|
|
|
import httpx
|
|
|
|
|
|
|
|
|
|
logger = logging.getLogger(__name__)
|
|
|
|
|
|
2026-06-29 14:22:33 -04:00
|
|
|
# Sea Haven fork identity: commits AND PRs come in as our GitHub App bot
|
|
|
|
|
# `seahaven-openswe[bot]` (user id 296972425) so Slack/dashboard/schedule runs are
|
|
|
|
|
# attributed to the app, not the triggering user (deterministic; eliminates the
|
|
|
|
|
# self-review 422). The numeric noreply is the canonical GitHub form.
|
|
|
|
|
# NOTE (Adam, 2026-06-29 — ACCEPTED RISK): the `<id>+<login>@users.noreply` form
|
|
|
|
|
# may NOT resolve to a GitHub account Vercel preview deploys accept (the upstream
|
|
|
|
|
# `open-swe[bot]` hit exactly this and worked around it with a non-numeric
|
|
|
|
|
# address). We deliberately accept that risk here in exchange for a consistent
|
|
|
|
|
# bot identity across commits + PRs. If Vercel preview deploys on a target repo
|
|
|
|
|
# start rejecting our commits, this is the cause — revert to a resolvable address.
|
|
|
|
|
OPEN_SWE_BOT_NAME = "seahaven-openswe[bot]"
|
|
|
|
|
OPEN_SWE_BOT_EMAIL = "296972425+seahaven-openswe[bot]@users.noreply.github.com"
|
2026-03-25 13:39:33 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
@dataclass(frozen=True)
|
|
|
|
|
class CollaboratorIdentity:
|
|
|
|
|
"""Identity used for git trailers and PR attribution."""
|
|
|
|
|
|
|
|
|
|
display_name: str
|
|
|
|
|
commit_name: str
|
|
|
|
|
commit_email: str
|
2026-06-02 09:27:51 -07:00
|
|
|
github_login: str = ""
|
|
|
|
|
|
|
|
|
|
@property
|
|
|
|
|
def pr_attribution_name(self) -> str:
|
|
|
|
|
"""Display name with GitHub login when available."""
|
|
|
|
|
if self.github_login and self.github_login != self.display_name:
|
|
|
|
|
return f"{self.display_name} (@{self.github_login})"
|
|
|
|
|
return self.display_name
|
2026-03-25 13:39:33 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
def _normalize_text(value: Any) -> str:
|
|
|
|
|
return value.strip() if isinstance(value, str) else ""
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def _github_noreply_email(login: str, user_id: Any = None) -> str:
|
|
|
|
|
normalized_login = _normalize_text(login)
|
|
|
|
|
if not normalized_login:
|
|
|
|
|
return ""
|
|
|
|
|
|
|
|
|
|
normalized_user_id = str(user_id).strip() if user_id is not None else ""
|
|
|
|
|
if normalized_user_id:
|
|
|
|
|
return f"{normalized_user_id}+{normalized_login}@users.noreply.github.com"
|
|
|
|
|
return f"{normalized_login}@users.noreply.github.com"
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def _identity_from_github_token(github_token: str | None) -> CollaboratorIdentity | None:
|
|
|
|
|
if not github_token:
|
|
|
|
|
return None
|
|
|
|
|
|
|
|
|
|
try:
|
|
|
|
|
response = httpx.get(
|
|
|
|
|
"https://api.github.com/user",
|
|
|
|
|
headers={
|
|
|
|
|
"Authorization": f"Bearer {github_token}",
|
|
|
|
|
"Accept": "application/vnd.github+json",
|
|
|
|
|
"X-GitHub-Api-Version": "2022-11-28",
|
|
|
|
|
},
|
|
|
|
|
timeout=5.0,
|
|
|
|
|
)
|
|
|
|
|
if response.status_code != 200: # noqa: PLR2004
|
|
|
|
|
logger.debug("GitHub user lookup returned %s", response.status_code)
|
|
|
|
|
return None
|
|
|
|
|
|
|
|
|
|
payload = response.json()
|
|
|
|
|
login = _normalize_text(payload.get("login"))
|
|
|
|
|
display_name = _normalize_text(payload.get("name")) or login
|
|
|
|
|
commit_email = _github_noreply_email(login, payload.get("id")) or _normalize_text(
|
|
|
|
|
payload.get("email")
|
|
|
|
|
)
|
|
|
|
|
if not display_name or not commit_email:
|
|
|
|
|
return None
|
|
|
|
|
if commit_email == OPEN_SWE_BOT_EMAIL and display_name == OPEN_SWE_BOT_NAME:
|
|
|
|
|
return None
|
|
|
|
|
return CollaboratorIdentity(
|
|
|
|
|
display_name=display_name,
|
|
|
|
|
commit_name=display_name,
|
|
|
|
|
commit_email=commit_email,
|
2026-06-02 09:27:51 -07:00
|
|
|
github_login=login,
|
2026-03-25 13:39:33 -07:00
|
|
|
)
|
|
|
|
|
except httpx.HTTPError:
|
|
|
|
|
logger.debug("Failed to resolve GitHub user identity from token", exc_info=True)
|
|
|
|
|
return None
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def _identity_from_config(config: dict[str, Any]) -> CollaboratorIdentity | None:
|
|
|
|
|
configurable = config.get("configurable", {})
|
2026-06-02 09:27:51 -07:00
|
|
|
slack_thread = configurable.get("slack_thread", {})
|
|
|
|
|
linear_issue = configurable.get("linear_issue", {})
|
|
|
|
|
|
|
|
|
|
display_name = (
|
|
|
|
|
_normalize_text(slack_thread.get("triggering_user_name"))
|
|
|
|
|
or _normalize_text(linear_issue.get("triggering_user_name"))
|
|
|
|
|
or _normalize_text(configurable.get("user_email")).split("@", 1)[0]
|
|
|
|
|
)
|
2026-03-25 13:39:33 -07:00
|
|
|
|
|
|
|
|
github_login = _normalize_text(configurable.get("github_login"))
|
|
|
|
|
if github_login:
|
|
|
|
|
github_user_id = configurable.get("github_user_id")
|
feat: Store-backed GitHub/Slack user mapping (self-service + admin) (#1369)
* Replace hardcoded GitHub-email map with Store-backed user mapping
Move the static GITHUB_USER_EMAIL_MAP to a Store-backed bidirectional
mapping (GitHub login <-> work email <-> optional Slack ID) with an
in-process cache, self-service onboarding, and admin management.
- agent/dashboard/user_mappings.py: Store CRUD + login/email/slack-id
indexes, sync cache readers for hot paths, async fallthrough, and a
bulk_import that preserves existing richer records.
- Migrate all read sites (auth.py, agent_overrides.py, authorship.py,
github_comments.py, webapp.py x2) off the dict.
- Unmapped Slack tags now run on the GitHub App installation token
(use_installation_token_fallback) and get an ephemeral "link your
GitHub account" prompt carrying the Slack id + email via a signed
account-link token threaded through the OAuth state.
- OAuth callback completes a self-service (org-gated) mapping from that
token, falling back to the verified GitHub email.
- Admin CRUD endpoints + one-time legacy import; dashboard UI section.
- Legacy dict retained only as the import payload (no longer read).
Tests: mapping store, account-link round-trip + completion, mapped vs
unmapped Slack flows; existing trust-gate tests updated to prime cache.
* Address review: cold-cache email resolution + stale alias de-indexing
- agent_overrides: add resolve_login_from_email_async that falls through to
the Store on a cold cache; use it at the async repo-resolution call sites
(Slack repo config, Linear comment, owner-metadata) so a mapped user still
resolves to their GitHub login + dashboard default_repo on a fresh worker.
- user_mappings.upsert_mapping: de-index the existing login before re-indexing
so a changed email/Slack id no longer leaves stale aliases resolving to the
login in-process.
- Tests for both fixes; update Slack repo-config test to patch the async resolver.
2026-06-01 14:37:19 -07:00
|
|
|
from ..dashboard.user_mappings import cached_email_for_login
|
|
|
|
|
|
2026-03-25 13:39:33 -07:00
|
|
|
commit_email = _github_noreply_email(github_login, github_user_id) or _normalize_text(
|
feat: Store-backed GitHub/Slack user mapping (self-service + admin) (#1369)
* Replace hardcoded GitHub-email map with Store-backed user mapping
Move the static GITHUB_USER_EMAIL_MAP to a Store-backed bidirectional
mapping (GitHub login <-> work email <-> optional Slack ID) with an
in-process cache, self-service onboarding, and admin management.
- agent/dashboard/user_mappings.py: Store CRUD + login/email/slack-id
indexes, sync cache readers for hot paths, async fallthrough, and a
bulk_import that preserves existing richer records.
- Migrate all read sites (auth.py, agent_overrides.py, authorship.py,
github_comments.py, webapp.py x2) off the dict.
- Unmapped Slack tags now run on the GitHub App installation token
(use_installation_token_fallback) and get an ephemeral "link your
GitHub account" prompt carrying the Slack id + email via a signed
account-link token threaded through the OAuth state.
- OAuth callback completes a self-service (org-gated) mapping from that
token, falling back to the verified GitHub email.
- Admin CRUD endpoints + one-time legacy import; dashboard UI section.
- Legacy dict retained only as the import payload (no longer read).
Tests: mapping store, account-link round-trip + completion, mapped vs
unmapped Slack flows; existing trust-gate tests updated to prime cache.
* Address review: cold-cache email resolution + stale alias de-indexing
- agent_overrides: add resolve_login_from_email_async that falls through to
the Store on a cold cache; use it at the async repo-resolution call sites
(Slack repo config, Linear comment, owner-metadata) so a mapped user still
resolves to their GitHub login + dashboard default_repo on a fresh worker.
- user_mappings.upsert_mapping: de-index the existing login before re-indexing
so a changed email/Slack id no longer leaves stale aliases resolving to the
login in-process.
- Tests for both fixes; update Slack repo-config test to patch the async resolver.
2026-06-01 14:37:19 -07:00
|
|
|
cached_email_for_login(github_login)
|
2026-03-25 13:39:33 -07:00
|
|
|
)
|
|
|
|
|
if commit_email:
|
2026-06-02 09:27:51 -07:00
|
|
|
commit_name = display_name or github_login
|
2026-03-25 13:39:33 -07:00
|
|
|
return CollaboratorIdentity(
|
2026-06-02 09:27:51 -07:00
|
|
|
display_name=commit_name,
|
|
|
|
|
commit_name=commit_name,
|
2026-03-25 13:39:33 -07:00
|
|
|
commit_email=commit_email,
|
2026-06-02 09:27:51 -07:00
|
|
|
github_login=github_login,
|
2026-03-25 13:39:33 -07:00
|
|
|
)
|
|
|
|
|
commit_email = _normalize_text(configurable.get("user_email")) or _normalize_text(
|
|
|
|
|
slack_thread.get("triggering_user_email")
|
|
|
|
|
)
|
|
|
|
|
if display_name and commit_email:
|
|
|
|
|
return CollaboratorIdentity(
|
|
|
|
|
display_name=display_name,
|
|
|
|
|
commit_name=display_name,
|
|
|
|
|
commit_email=commit_email,
|
|
|
|
|
)
|
|
|
|
|
return None
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def resolve_triggering_user_identity(
|
|
|
|
|
config: dict[str, Any],
|
|
|
|
|
github_token: str | None = None,
|
|
|
|
|
) -> CollaboratorIdentity | None:
|
|
|
|
|
"""Resolve the triggering user's git identity.
|
|
|
|
|
|
|
|
|
|
Prefer the GitHub account identity derived from the token when available.
|
|
|
|
|
Fall back to config metadata when the run originated from GitHub or when
|
|
|
|
|
Slack/Linear supplied an explicit user name and email.
|
|
|
|
|
"""
|
|
|
|
|
|
|
|
|
|
return _identity_from_github_token(github_token) or _identity_from_config(config)
|