Skip to content

test(bundle): drive the authorization policy arms of auth.ts (members/collaborators/root-OWNERS admits, trusted refusal, config-load failures, empty login) through dist/index.js - #378

Open
hivecommons-hive[bot] wants to merge 1 commit into
mainfrom
quality/test-authorization-policy-arms
Open

hivecommons-hive[bot] wants to merge 1 commit into
mainfrom
quality/test-authorization-policy-arms

Conversation

@hivecommons-hive

Copy link
Copy Markdown
Contributor

Test Improvement

Adds __tests__/bundle/authorizationPolicyArms.test.ts: seven issue_comment runs through dist/index.js against the fake GitHub covering the authorization policy arms of src/utils/auth.ts that authorization.test.ts (from #367) leaves out —

  • /triage accepted under labels: members by an org member → policyAllows admits on the membership read (L313), no collaborator read
  • /triage accepted under labels: collaborators by a collaborator → admits on the collaborator read (L316), no membership read
  • /triage accepted under labels: trusted by a root-OWNERS reviewer who is neither member, collaborator nor in users → rootOwnersIncludes admits from the OWNERS file (L460–462)
  • /triage accepted under labels: collaborators from a payload without comment.user.login → refused before any read (L304)
  • /close by a stranger with an authorization section that does not parse (close: everyone) → closePolicyAllows returns false (L365) after loadAuthorization warns (L377–378); exit 0, no PATCH
  • /lgtm on a PR without OWNERS files under review: trusted, users: [friend] by outsider → refused with … or listed in authorization.users (L270), configuration read only after the membership reads refuse
  • /lgtm on a PR without OWNERS files with an authorization section that does not parse (review: anyone) → warns and falls back to the members default (the .catch(() => defaultAuthorization) on L265)

Measured on main @ 5061d57 with npm run test:coverage:e2e: auth.ts 70.14 % → 82.08 % lines; newly reached auth.ts lines 265, 270, 304, 313, 316, 365, 377–378, 460–462 (plus the retrieveOwnersFile success lines 480–499, which #283/#331 also reach). Files/functions claimed: __tests__/bundle/authorizationPolicyArms.test.ts only; policyAllows, closePolicyAllows, loadAuthorization, rootOwnersIncludes and the review fallback of assertAuthorizedByOwnersOrMembership. Disjoint from #283/#331 (assertRootOwner on an issue), #355 (/approve membership refusals) and #326 (hold.ts).

Uses comment, configReads, helpersFor, membershipReads, ownersReads from ./helpers; no helper, source or dist/ changes. Error and warning assertions check fragments only.

Verified locally: npx eslint __tests__/bundle/authorizationPolicyArms.test.ts clean; npx vitest run __tests__/bundle/authorizationPolicyArms.test.ts → 7 passed; npm run test:coverage:e2e → 222 passed.

Related Issue

Closes #377


Filed by quality agent (hold-gated mode). Human review required.

— hive: agent=quality backend=copilot model=claude-fable-5.1

…dist/index.js

policyAllows' member, collaborator and empty-login arms, the trusted
fallback to the root OWNERS file (rootOwnersIncludes), closePolicyAllows'
and the review fallback's behaviour when the authorization section does
not parse, and review: trusted refusing a user outside authorization.users.

Signed-off-by: quality <quality@hive.kubestellar.io>
@hivecommons-hive
hivecommons-hive Bot requested a review from jpmcb as a code owner October 8, 2026 02:28
@hivecommons-hive hivecommons-hive Bot added the hold Indicates that a PR should not merge because someone has issued a /hold command. label Oct 8, 2026
@hivecommons-hive

Copy link
Copy Markdown
Contributor Author

Important

Held for human review by the hive's ACMM level gate.

This PR was opened by the "quality" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the outreach agent is always held because it publishes project-facing communication.

Hive will keep the hold label until a human removes it. Operators can make a deliberate one-off release during an ACMM level change with release_level_holds=true, but level changes never release this hold automatically.

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Please add a kind label with /kind failing-test or /kind cleanup.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hold Indicates that a PR should not merge because someone has issued a /hold command. needs-kind

Projects

None yet

0 participants