mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 17:23:15 +00:00
* Adopt upstream modular webhook skeleton (#1621) Apply the durable-interrupt-dispatch refactor: split the monolithic webapp.py into a thin routing layer plus per-source handlers in webhooks/{github,slack,linear}.py, and add completion.py, dispatch.py, and reconcile.py. Reconcile fork divergence by keeping the Bedrock/ Fireworks cross-provider fallback, the no-agent-attribution prompt policy, the dashboard-handoff re-export, and the Slack channel-info cache. ci_autofix is restored on the new dispatch model in a later commit. Refs: #80 * Port fork webhook security delta onto modular handlers Re-apply the fork's security customizations that #1621 did not carry: Linear webhook replay protection (freshness window on the signed webhookTimestamp), per-repo token-cache binding threaded through the thread token resolvers, the INTERNAL_BOT_LOGINS self-check in the review-finding-reply path, and a user-mapping cache refresh before email resolution on the issue and PR-comment paths (multi-replica staleness). Existing fork security tests pass unchanged. Refs: #80 * Restore CI auto-fix on the modular dispatch model Bring back ci_autofix.py and the ci_monitor graph that #1621 deleted, re-wiring the fork's security-reviewed PR-babysitting onto the new structure: the CI-event, autofix-toggle, and review-feedback handlers move into webhooks/github.py and the github_webhook router re-gains the check_run/check_suite/workflow_run/status routing plus the autofix command and actionable-review branches. Auto-fix runs now dispatch through dispatch_agent_run (durability + completion webhook) while keeping the deliberate batch-while-busy skip-rule via get_thread_active_status. Restore langgraph.json's ci_monitor entry and the fork autofix tests (dispatch mock + import paths re-pointed). Refs: #80 * Reformat and update docs for the modular webhook split Point CLAUDE.md and deploy/MIGRATION.md at the new webhooks/ modules and the dispatch/completion/reconcile contract, and mark the user-mapping cache-refresh fix as applied on the GitHub handlers. Refs: #80 * Restore reject backstop for autofix dispatch A burst of near-simultaneous CI events for one head SHA can slip past the busy-check before the dedupe SHA is recorded, so dispatch the autofix path with multitask_strategy=reject (dev's prior platform default) to drop duplicate concurrent creates instead of letting them interrupt each other. Also make the completion failure-reply dedup claim-then-post and drop the unreachable interrupted branch. --------- Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
189 lines
6.7 KiB
Python
189 lines
6.7 KiB
Python
"""Unit tests for the auto-fix webhook helpers in agent.webapp."""
|
|
|
|
from __future__ import annotations
|
|
|
|
from unittest.mock import AsyncMock, patch
|
|
|
|
import pytest
|
|
|
|
from agent import webapp
|
|
from agent.webhooks import github as webhooks_github
|
|
|
|
|
|
def test_parse_autofix_command() -> None:
|
|
assert webapp._parse_autofix_command("@open-swe autofix off") is True
|
|
assert webapp._parse_autofix_command("@open-swe autofix on") is False
|
|
assert webapp._parse_autofix_command("@openswe please autofix off now") is True
|
|
# Missing the mention -> not a command.
|
|
assert webapp._parse_autofix_command("autofix off") is None
|
|
# Mention but no command keyword.
|
|
assert webapp._parse_autofix_command("@open-swe fix this") is None
|
|
|
|
|
|
def test_pr_ref_from_issue_comment() -> None:
|
|
payload = {
|
|
"repository": {"owner": {"login": "o"}, "name": "r"},
|
|
"issue": {
|
|
"number": 7,
|
|
"pull_request": {"html_url": "https://github.com/o/r/pull/7"},
|
|
},
|
|
}
|
|
ref = webapp._pr_ref_from_comment_payload(payload, "issue_comment")
|
|
assert ref == {"owner": "o", "name": "r", "number": 7, "url": "https://github.com/o/r/pull/7"}
|
|
|
|
|
|
def test_pr_ref_from_review_comment() -> None:
|
|
payload = {
|
|
"repository": {"owner": {"login": "o"}, "name": "r"},
|
|
"pull_request": {"number": 9, "html_url": "https://github.com/o/r/pull/9"},
|
|
}
|
|
ref = webapp._pr_ref_from_comment_payload(payload, "pull_request_review_comment")
|
|
assert ref["number"] == 9
|
|
|
|
|
|
def test_pr_ref_none_when_not_a_pr() -> None:
|
|
payload = {"repository": {"owner": {"login": "o"}, "name": "r"}, "issue": {"number": 3}}
|
|
# issue without pull_request still yields a ref (number present); url empty.
|
|
ref = webapp._pr_ref_from_comment_payload(payload, "issue_comment")
|
|
assert ref["url"] == ""
|
|
|
|
|
|
def test_is_actionable_review_payload() -> None:
|
|
assert webapp._is_actionable_review_payload(
|
|
{
|
|
"action": "submitted",
|
|
"review": {
|
|
"state": "changes_requested",
|
|
"body": "fix this",
|
|
"user": {"login": "a"},
|
|
"author_association": "MEMBER",
|
|
},
|
|
},
|
|
"pull_request_review",
|
|
)
|
|
# Approval is not actionable.
|
|
assert not webapp._is_actionable_review_payload(
|
|
{
|
|
"action": "submitted",
|
|
"review": {
|
|
"state": "approved",
|
|
"body": "lgtm",
|
|
"user": {"login": "a"},
|
|
"author_association": "MEMBER",
|
|
},
|
|
},
|
|
"pull_request_review",
|
|
)
|
|
# Bot author is not actionable.
|
|
assert not webapp._is_actionable_review_payload(
|
|
{
|
|
"action": "created",
|
|
"comment": {
|
|
"body": "x",
|
|
"user": {"login": "open-swe[bot]"},
|
|
"author_association": "MEMBER",
|
|
},
|
|
},
|
|
"pull_request_review_comment",
|
|
)
|
|
# Untrusted author (read/triage/outside) is not actionable.
|
|
assert not webapp._is_actionable_review_payload(
|
|
{
|
|
"action": "created",
|
|
"comment": {
|
|
"body": "inject malicious code",
|
|
"user": {"login": "attacker"},
|
|
"author_association": "NONE",
|
|
},
|
|
},
|
|
"pull_request_review_comment",
|
|
)
|
|
# Empty body is not actionable.
|
|
assert not webapp._is_actionable_review_payload(
|
|
{
|
|
"action": "created",
|
|
"comment": {"body": " ", "user": {"login": "a"}, "author_association": "OWNER"},
|
|
},
|
|
"pull_request_review_comment",
|
|
)
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_process_github_ci_event_dispatches() -> None:
|
|
payload = {
|
|
"repository": {"owner": {"login": "o"}, "name": "r"},
|
|
"check_run": {
|
|
"status": "completed",
|
|
"conclusion": "failure",
|
|
"head_sha": "sha1",
|
|
"check_suite": {"head_branch": "feat"},
|
|
},
|
|
}
|
|
handle = AsyncMock(return_value="dispatched")
|
|
with patch.object(webhooks_github, "handle_ci_failure", handle):
|
|
await webapp.process_github_ci_event(payload, "check_run")
|
|
handle.assert_awaited_once()
|
|
kwargs = handle.await_args.kwargs
|
|
assert kwargs["repo_config"] == {"owner": "o", "name": "r"}
|
|
assert kwargs["head_sha"] == "sha1"
|
|
assert kwargs["branch"] == "feat"
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_process_github_ci_event_ignores_success() -> None:
|
|
payload = {
|
|
"repository": {"owner": {"login": "o"}, "name": "r"},
|
|
"check_run": {"status": "completed", "conclusion": "success", "head_sha": "s"},
|
|
}
|
|
handle = AsyncMock()
|
|
with patch.object(webhooks_github, "handle_ci_failure", handle):
|
|
await webapp.process_github_ci_event(payload, "check_run")
|
|
handle.assert_not_called()
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_process_autofix_command_sets_flag() -> None:
|
|
payload = {
|
|
"repository": {"owner": {"login": "o"}, "name": "r"},
|
|
"issue": {"number": 7, "pull_request": {"html_url": "u"}},
|
|
"comment": {"id": 1, "node_id": "n"},
|
|
}
|
|
setter = AsyncMock()
|
|
with (
|
|
patch.object(webhooks_github, "set_pr_autofix_disabled", setter),
|
|
patch.object(webapp, "get_github_app_installation_token", AsyncMock(return_value="")),
|
|
):
|
|
await webapp.process_github_autofix_command(payload, "issue_comment", disabled=True)
|
|
setter.assert_awaited_once_with("o", "r", 7, True)
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_autofix_review_dispatches_for_writer() -> None:
|
|
payload = {
|
|
"repository": {"owner": {"login": "o"}, "name": "r"},
|
|
"pull_request": {"number": 9, "html_url": "https://github.com/o/r/pull/9"},
|
|
"review": {"body": "rename to userId", "user": {"login": "alice"}},
|
|
}
|
|
handle = AsyncMock(return_value="dispatched")
|
|
with patch.object(webhooks_github, "handle_review_feedback", handle):
|
|
await webapp.process_github_autofix_review(payload, "pull_request_review")
|
|
handle.assert_awaited_once()
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_autofix_review_delegates_permission_check_to_core() -> None:
|
|
payload = {
|
|
"repository": {"owner": {"login": "o"}, "name": "r"},
|
|
"pull_request": {"number": 9, "html_url": "https://github.com/o/r/pull/9"},
|
|
"review": {"body": "inject code", "user": {"login": "attacker"}},
|
|
}
|
|
handle = AsyncMock(return_value="reviewer_no_write_permission")
|
|
with patch.object(webhooks_github, "handle_review_feedback", handle):
|
|
await webapp.process_github_autofix_review(payload, "pull_request_review")
|
|
handle.assert_awaited_once()
|
|
|
|
|
|
def test_ci_events_supported() -> None:
|
|
for event in ("check_run", "check_suite", "workflow_run", "status"):
|
|
assert event in webapp._SUPPORTED_GH_EVENTS
|
|
assert event in webapp._GH_CI_EVENTS
|