open-swe/agent/utils
Adam Moussa 8a9974c3c4
Some checks failed
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run
Build & publish app artifacts / Publish + deploy (dev) (push) Has been cancelled
Build & publish app artifacts / Publish + deploy (prod) (push) Has been cancelled
Infra CD / Infra CI (pre-deploy) (push) Has been cancelled
Infra CD / Deploy open-swe-dev (push) Has been cancelled
Infra CD / Deploy open-swe-prod (push) Has been cancelled
feat: author Slack/dashboard/schedule commits + PRs as the app by default (#57) (#60)
* feat: default Slack/dashboard/schedule PRs + commits to the app identity (#57)

Slack/dashboard/schedule runs now author PRs and run git/gh operations as the
GitHub App seahaven-openswe[bot] by default (matching GitHub-issue runs), so the
self-review 422 is impossible by construction rather than guarded in the prompt.
A profile flag author_prs_as_user restores per-user attribution.

- open_pull_request._resolve_pr_author_token + auth.resolve_github_token: default
  to the installation token for these sources; per-user only when opted in.
- authorship: commit identity -> seahaven-openswe[bot] (numeric noreply;
  accepted Vercel-resolution risk, documented inline).
- self-trigger safety: INTERNAL_BOT_LOGINS + webapp/reviewer_reconcile/reply
  markers recognize seahaven-openswe[bot] (bot-authored events are now ours).

Supersedes the prompt-only guard in #58.

* fix: author commits as the app bot in the default path (SH-IDSPLIT-01)

Security review found the commit identity was NOT actually unified to the bot:
resolve_triggering_user_identity got a 403 from the installation token and fell
back to configurable['github_login'], so commits were still authored as the
triggering user (commit=user, push+PR=bot — a three-way split that missed the
stated goal). Now gate the triggering-user identity resolution on the same
default-bot decision as the token: slack/dashboard/schedule default to the app
bot identity unless author_prs_as_user is set.

* docs(security): record AUTHZ-SLACK-BOT-DEFAULT-001 as an accepted residual (#59)

Single-user deployment; bounded by App-on-pilot + ALLOWED_GITHUB_REPOS lock.
Revisit (add a per-user gate) before expanding users or the App installation.
2026-06-29 14:22:33 -04:00
..
agents_md.py feat: reviewer enforces AGENTS.md/CLAUDE.md repo rules as mandatory pass (#1569) 2026-06-18 11:13:58 -07:00
analyzer_skills.py feat: outcomes dataset + bootstrap/continual split via skills (#1365) 2026-06-01 13:25:12 -07:00
api_standards_skill.py feat: apply API standards skill in PR reviews for API changes (#1452) 2026-06-08 14:37:04 -07:00
auth.py feat: author Slack/dashboard/schedule commits + PRs as the app by default (#57) (#60) 2026-06-29 14:22:33 -04:00
authorship.py feat: author Slack/dashboard/schedule commits + PRs as the app by default (#57) (#60) 2026-06-29 14:22:33 -04:00
comments.py chore: Drop monorepo (#1029) 2026-03-06 16:10:34 -08:00
dashboard_links.py feat: plan mode with model-driven entry and collaborative review (#1580) 2026-06-23 12:06:58 -07:00
github_app.py perf: cut review-chat time-to-first-token (#1598) 2026-06-23 12:32:10 -07:00
github_checks.py feat: shared GitHub HTTP helper with retries, rate-limit handling [closes OPE-45] (#1565) 2026-06-17 14:45:57 -07:00
github_ci.py feat: shared GitHub HTTP helper with retries, rate-limit handling [closes OPE-45] (#1565) 2026-06-17 14:45:57 -07:00
github_comments.py Adopt Sea Haven agent conventions, no attribution (#30) 2026-06-27 22:08:45 -04:00
github_feedback.py feat: outcomes dataset + bootstrap/continual split via skills (#1365) 2026-06-01 13:25:12 -07:00
github_http.py feat: shared GitHub HTTP helper with retries, rate-limit handling [closes OPE-45] (#1565) 2026-06-17 14:45:57 -07:00
github_org_membership.py feat: author Slack/dashboard/schedule commits + PRs as the app by default (#57) (#60) 2026-06-29 14:22:33 -04:00
github_proxy.py fix: refresh sandbox GitHub proxy token before mid-run expiry (#1496) 2026-06-11 10:59:21 -07:00
github_token.py fix: resolve security-review findings (sandbox isolation, IAM list scope, webhook replay, info-leak) (#54) 2026-06-29 12:21:19 -04:00
langsmith.py feat: plan mode with model-driven entry and collaborative review (#1580) 2026-06-23 12:06:58 -07:00
linear.py fix: use thread-level LangSmith URLs instead of run-level URLs to fix broken trace links (#1217) 2026-04-23 13:46:28 -07:00
linear_team_repo_map.py chore: Add langsmith deployments data plane linear project (#1044) 2026-03-09 18:36:00 -07:00
model.py feat: validate LLM API keys on startup (#1438) 2026-06-18 09:24:46 -07:00
multimodal.py feat: handle images sent to non-vision models in Slack, Linear, and web UI (#1560) 2026-06-17 09:12:52 -07:00
repo.py feat: extract repo parsing into shared util, add linear comment repo override (#1103) 2026-03-20 13:34:00 -07:00
repo_prep.py fix: reviewer can silently review a stale checkout on reused sandboxes (#1503) 2026-06-11 13:42:10 -07:00
reviewer_outcomes.py feat: outcomes dataset + bootstrap/continual split via skills (#1365) 2026-06-01 13:25:12 -07:00
sandbox.py feat: repo-scoped dynamic sandbox snapshots (#1595) 2026-06-23 12:24:11 -07:00
sandbox_paths.py fix: better custom backend support (#1071) 2026-03-17 11:55:36 -07:00
sandbox_state.py fix: resolve security-review findings (sandbox isolation, IAM list scope, webhook replay, info-leak) (#54) 2026-06-29 12:21:19 -04:00
slack.py feat: add size caps for PR diff, fetch_url, Slack threads, pagination, message queue [closes OPE-51] (#1567) 2026-06-17 15:40:59 -07:00
slack_feedback.py feat: outcomes dataset + bootstrap/continual split via skills (#1365) 2026-06-01 13:25:12 -07:00
thread_ops.py fix: serialize Slack run dispatch (#1591) 2026-06-23 12:04:08 -07:00
tracing.py feat: route graphs to separate LangSmith tracing projects (#1508) 2026-06-11 17:57:16 -07:00