mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 17:23:15 +00:00
Some checks failed
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run
Build & publish app artifacts / Publish + deploy (dev) (push) Has been cancelled
Build & publish app artifacts / Publish + deploy (prod) (push) Has been cancelled
Infra CD / Infra CI (pre-deploy) (push) Has been cancelled
Infra CD / Deploy open-swe-dev (push) Has been cancelled
Infra CD / Deploy open-swe-prod (push) Has been cancelled
* feat: default Slack/dashboard/schedule PRs + commits to the app identity (#57) Slack/dashboard/schedule runs now author PRs and run git/gh operations as the GitHub App seahaven-openswe[bot] by default (matching GitHub-issue runs), so the self-review 422 is impossible by construction rather than guarded in the prompt. A profile flag author_prs_as_user restores per-user attribution. - open_pull_request._resolve_pr_author_token + auth.resolve_github_token: default to the installation token for these sources; per-user only when opted in. - authorship: commit identity -> seahaven-openswe[bot] (numeric noreply; accepted Vercel-resolution risk, documented inline). - self-trigger safety: INTERNAL_BOT_LOGINS + webapp/reviewer_reconcile/reply markers recognize seahaven-openswe[bot] (bot-authored events are now ours). Supersedes the prompt-only guard in #58. * fix: author commits as the app bot in the default path (SH-IDSPLIT-01) Security review found the commit identity was NOT actually unified to the bot: resolve_triggering_user_identity got a 403 from the installation token and fell back to configurable['github_login'], so commits were still authored as the triggering user (commit=user, push+PR=bot — a three-way split that missed the stated goal). Now gate the triggering-user identity resolution on the same default-bot decision as the token: slack/dashboard/schedule default to the app bot identity unless author_prs_as_user is set. * docs(security): record AUTHZ-SLACK-BOT-DEFAULT-001 as an accepted residual (#59) Single-user deployment; bounded by App-on-pilot + ALLOWED_GITHUB_REPOS lock. Revisit (add a per-user gate) before expanding users or the App installation.
101 lines
3.4 KiB
Python
101 lines
3.4 KiB
Python
from __future__ import annotations
|
|
|
|
import asyncio
|
|
from typing import Any
|
|
|
|
from langgraph.config import get_config
|
|
|
|
from ..reviewer_findings import (
|
|
FindingInteraction,
|
|
ReviewerThreadMissingError,
|
|
append_finding_interaction,
|
|
get_finding,
|
|
get_thread_id_from_runtime,
|
|
thread_missing_tool_result,
|
|
update_finding_fields,
|
|
)
|
|
from ..reviewer_publish import reply_to_review_comment
|
|
from ..utils.github_token import get_github_token
|
|
|
|
|
|
def reply_to_finding_thread(finding_id: str, body: str) -> dict[str, Any]:
|
|
"""Reply to the GitHub review thread for a tracked finding."""
|
|
if not body.strip():
|
|
return {"success": False, "error": "Reply body is required"}
|
|
|
|
config = get_config()
|
|
configurable = config.get("configurable", {}) if isinstance(config, dict) else {}
|
|
repo_config = configurable.get("repo") if isinstance(configurable, dict) else None
|
|
pr_number = configurable.get("pr_number") if isinstance(configurable, dict) else None
|
|
if (
|
|
not isinstance(repo_config, dict)
|
|
or not repo_config.get("owner")
|
|
or not repo_config.get("name")
|
|
or not isinstance(pr_number, int)
|
|
):
|
|
return {"success": False, "error": "Missing repo or PR info in run config"}
|
|
|
|
token = get_github_token()
|
|
if not token:
|
|
return {"success": False, "error": "No GitHub token available"}
|
|
|
|
try:
|
|
return asyncio.run(
|
|
_reply_to_finding_thread_async(
|
|
finding_id=finding_id,
|
|
body=body,
|
|
owner=str(repo_config["owner"]),
|
|
repo=str(repo_config["name"]),
|
|
pr_number=pr_number,
|
|
token=token,
|
|
)
|
|
)
|
|
except ReviewerThreadMissingError as exc:
|
|
return thread_missing_tool_result(exc)
|
|
|
|
|
|
async def _reply_to_finding_thread_async(
|
|
*,
|
|
finding_id: str,
|
|
body: str,
|
|
owner: str,
|
|
repo: str,
|
|
pr_number: int,
|
|
token: str,
|
|
) -> dict[str, Any]:
|
|
thread_id = get_thread_id_from_runtime()
|
|
finding = await get_finding(thread_id, finding_id)
|
|
if finding is None:
|
|
return {"success": False, "error": f"No finding found with id {finding_id}"}
|
|
|
|
comment_id = finding.get("github_review_comment_id")
|
|
if not isinstance(comment_id, int):
|
|
return {"success": False, "error": "Finding has no GitHub review comment mapping"}
|
|
|
|
response = await reply_to_review_comment(
|
|
owner=owner,
|
|
repo=repo,
|
|
pr_number=pr_number,
|
|
review_comment_id=comment_id,
|
|
body=body.strip(),
|
|
token=token,
|
|
)
|
|
if response is None:
|
|
return {"success": False, "error": "GitHub did not accept the reply"}
|
|
|
|
reply_id = response.get("id")
|
|
updates: dict[str, Any] = {"last_reconciliation_note": "Replied to GitHub review thread."}
|
|
if isinstance(reply_id, int):
|
|
updates["last_review_reply_comment_id"] = reply_id
|
|
updated = await update_finding_fields(thread_id, finding_id, updates)
|
|
interaction: FindingInteraction = {
|
|
"kind": "bot_reply",
|
|
"github_comment_id": reply_id if isinstance(reply_id, int) else None,
|
|
"github_parent_comment_id": comment_id,
|
|
"author": "seahaven-openswe[bot]",
|
|
"body": body.strip(),
|
|
"created_at": "",
|
|
"needs_reassessment": False,
|
|
}
|
|
updated = await append_finding_interaction(thread_id, finding_id, interaction)
|
|
return {"success": True, "finding": updated, "reply_id": reply_id}
|