* Lock dashboard login to GitHub org members
Add an org-membership gate to the dashboard OAuth callback. After
resolving the GitHub login, enforce_org_login_gate(login) checks the
existing ALLOWED_GITHUB_ORGS allowlist before issuing a session.
- Reuses ALLOWED_GITHUB_ORGS (no new config knob) and
is_user_active_org_member (installation-token check, so no extra
OAuth scope and private memberships are visible).
- Fail-open when unset/blank so existing deployments keep working;
fail-closed on API errors.
- Gate runs before the session cookie/token is persisted.
Adds unit tests and documents the behavior in INSTALLATION.md.
* docs: document Organization Members permission required for org login gate
Adds a webhook-level check so only members of $PUBLIC_REPO_ORG_GATE
(e.g. langchain-ai) can trigger Open SWE via mentions or review
requests on public repositories. Private repos remain governed by the
existing org/repo allowlists. Internal bots bypass the gate.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Johannes du Plessis <51395795+johannes117@users.noreply.github.com>