Repository navigation
test(bundle): drive the authorization policy arms of auth.ts (members/collaborators/root-OWNERS admits, trusted refusal, config-load failures, empty login) through dist/index.js - #378
Open
hivecommons-hive[bot] wants to merge 1 commit into
Conversation
…dist/index.js policyAllows' member, collaborator and empty-login arms, the trusted fallback to the root OWNERS file (rootOwnersIncludes), closePolicyAllows' and the review fallback's behaviour when the authorization section does not parse, and review: trusted refusing a user outside authorization.users. Signed-off-by: quality <quality@hive.kubestellar.io>
Contributor
Author
|
Important Held for human review by the hive's ACMM level gate. This PR was opened by the "quality" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the Hive will keep the |
Contributor
|
Please add a kind label with |
This was referenced Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Test Improvement
Adds
__tests__/bundle/authorizationPolicyArms.test.ts: sevenissue_commentruns throughdist/index.jsagainst the fake GitHub covering theauthorizationpolicy arms ofsrc/utils/auth.tsthatauthorization.test.ts(from #367) leaves out —/triage acceptedunderlabels: membersby an org member →policyAllowsadmits on the membership read (L313), no collaborator read/triage acceptedunderlabels: collaboratorsby a collaborator → admits on the collaborator read (L316), no membership read/triage acceptedunderlabels: trustedby a root-OWNERS reviewer who is neither member, collaborator nor inusers→rootOwnersIncludesadmits from the OWNERS file (L460–462)/triage acceptedunderlabels: collaboratorsfrom a payload withoutcomment.user.login→ refused before any read (L304)/closeby a stranger with anauthorizationsection that does not parse (close: everyone) →closePolicyAllowsreturns false (L365) afterloadAuthorizationwarns (L377–378); exit 0, noPATCH/lgtmon a PR without OWNERS files underreview: trusted, users: [friend]byoutsider→ refused with… or listed in authorization.users(L270), configuration read only after the membership reads refuse/lgtmon a PR without OWNERS files with anauthorizationsection that does not parse (review: anyone) → warns and falls back to themembersdefault (the.catch(() => defaultAuthorization)on L265)Measured on
main@ 5061d57 withnpm run test:coverage:e2e:auth.ts70.14 % → 82.08 % lines; newly reachedauth.tslines 265, 270, 304, 313, 316, 365, 377–378, 460–462 (plus theretrieveOwnersFilesuccess lines 480–499, which #283/#331 also reach). Files/functions claimed:__tests__/bundle/authorizationPolicyArms.test.tsonly;policyAllows,closePolicyAllows,loadAuthorization,rootOwnersIncludesand thereviewfallback ofassertAuthorizedByOwnersOrMembership. Disjoint from #283/#331 (assertRootOwneron an issue), #355 (/approvemembership refusals) and #326 (hold.ts).Uses
comment,configReads,helpersFor,membershipReads,ownersReadsfrom./helpers; no helper, source ordist/changes. Error and warning assertions check fragments only.Verified locally:
npx eslint __tests__/bundle/authorizationPolicyArms.test.tsclean;npx vitest run __tests__/bundle/authorizationPolicyArms.test.ts→ 7 passed;npm run test:coverage:e2e→ 222 passed.Related Issue
Closes #377
Filed by quality agent (hold-gated mode). Human review required.
— hive: agent=quality backend=copilot model=claude-fable-5.1