Skip to content

fix(review): enforce inline comment gates#1548

Merged
JSONbored merged 2 commits into
mainfrom
codex/fix-inline-review-posting-authorization-issue
Jun 27, 2026
Merged

fix(review): enforce inline comment gates#1548
JSONbored merged 2 commits into
mainfrom
codex/fix-inline-review-posting-authorization-issue

Conversation

@JSONbored

Copy link
Copy Markdown
Owner

Motivation

  • Prevent AI-provided inlineFindings from causing unauthorized GitHub writes when the inline-comments feature is disabled by the operator flag, repo allowlist, or per-repo manifest toggle.
  • Close an authorization/configuration boundary: asking the model is not an authorization decision, so the write boundary must re-check the resolved gate.

Description

  • Ensure model-emitted inline findings are only propagated when the caller actually requested them by changing runGittensoryAiReview to return inlineFindings only when input.inlineFindings is truthy (stop propagating unexpected AI output). (src/services/ai-review.ts)
  • Add an explicit inlineCommentsEnabled parameter to the write boundary and make maybePostInlineComments return early when disabled, avoiding loading PR files or calling GitHub. (src/review/inline-comments.ts)
  • Compute and carry the resolved inline-comment decision through the review publish path and pass it into the write boundary when publishing reviews. (src/queue/processors.ts)
  • Add regression tests covering both layers: the AI-review path drops inline findings when not requested, and the posting path no-ops without loading files when inline comments are disabled. (test/unit/ai-review.test.ts, test/unit/inline-comments.test.ts)

Testing

  • Ran unit tests for the modified suites with npx vitest run test/unit/inline-comments.test.ts test/unit/ai-review.test.ts --reporter=verbose, and all tests in those files passed.
  • Ran tsc --noEmit via npm run typecheck, which succeeded with no type errors.
  • Verified git diff --check returned clean.
  • Started npm run test:coverage; the run was initiated but did not complete in this environment before the job was terminated.
  • npm audit --audit-level=moderate could not complete due to the registry audit endpoint returning 403 Forbidden in this environment.

Codex Task

@dosubot dosubot Bot added the size:S This PR changes 10-29 lines, ignoring generated files. label Jun 26, 2026
@superagent-security

Copy link
Copy Markdown

Superagent didn't find any vulnerabilities or security issues in this PR.

@codecov

codecov Bot commented Jun 26, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 95.38%. Comparing base (9e1c351) to head (d2ed105).
⚠️ Report is 4 commits behind head on main.
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #1548   +/-   ##
=======================================
  Coverage   95.38%   95.38%           
=======================================
  Files         201      201           
  Lines       21598    21601    +3     
  Branches     7807     7809    +2     
=======================================
+ Hits        20601    20604    +3     
  Misses        416      416           
  Partials      581      581           
Files with missing lines Coverage Δ
src/queue/processors.ts 87.44% <100.00%> (+0.01%) ⬆️
src/review/inline-comments.ts 100.00% <100.00%> (ø)
src/services/ai-review.ts 98.55% <100.00%> (ø)
🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@JSONbored JSONbored self-assigned this Jun 26, 2026
@JSONbored JSONbored added the gittensor:bug Gittensor-scored bug fix - worth 0.5x multiplier. label Jun 26, 2026
@gittensory-orb

gittensory-orb Bot commented Jun 27, 2026

Copy link
Copy Markdown

Warning

🟨🟨🟨🟨🟨🟨🟨🟨🟨🟨🟨🟨

⏸️ Gittensory review — held for maintainer review

5 files · 1 AI reviewers · no blockers · readiness 48/100 · CI green · blocked

⏸️ Held for maintainer review

Signal Result Evidence
Code review ✅ No blockers 1 reviewers, synthesized
Linked issue ⚠️ Missing No linked issue or no-issue rationale found.
Related work ⚠️ 3 scoped overlaps Top overlaps are listed below; lower-confidence bulk is hidden.
Review load ❌ 8/20 Readiness component derived from cached public PR metadata and labels; size label size:S.
Validation evidence ❌ 5/25 Cached preflight status is hold.
Open PR queue ❌ 3/10 48 open PR(s), 9 likely reviewable, 39 unlinked.
Contributor context ✅ Confirmed Gittensor contributor JSONbored; Gittensor profile; 81 PR(s), 261 issue(s).
Gate result ✅ Passing No configured blocker found.
Nits — 2 non-blocking
  • Repository config was not parsed
  • No linked issue detected — If this PR is intended to solve an issue, link it explicitly in the PR body.
Review context
  • Author: JSONbored
  • Role context: owner (maintainer lane)
  • Public audience mode: oss maintainer
  • Lane context: Repository registration is not available in the local Gittensory cache.
  • Public profile languages: not available
  • Official Gittensor activity: 81 PR(s), 261 issue(s).
  • Related work: Titles/paths share 6 meaningful terms. (PR #1391)
  • Related work: Titles/paths share 6 meaningful terms. (PR #1396)
  • Related work: Titles/paths share 7 meaningful terms. (PR #1398)
  • Additional title-only matches omitted; title-only overlap does not block.
Contributor next steps
  • Treat this as maintainer-lane context rather than normal contributor-lane activity.
  • Explain no-issue PR.
  • Review top overlaps.
  • Add scope summary.
  • Fix blocker.
  • Expect slower review.
  • Refresh registry data or choose a registered active repo.
  • Link the issue being solved, or explicitly explain why this is a no-issue PR.
  • Check active issues and PRs before submitting.
Signal definitions
  • Related work = same linked issue, overlapping active PRs, or title/path similarity.
  • Review load = cached public PR metadata such as size labels, changed paths, and preflight status.
  • Open PR queue = repo-wide review pressure; it is not a PR quality failure.
  • Contributor context = public GitHub/Gittensor identity context; non-Gittensor status is not a blocker.

🟩 Safe / merged · 🟦 Advisory · 🟨 Held for review · 🟥 Blocked / closed


💰 Earn for open-source contributions like this. Gittensor lets GitHub contributors earn for the work they already do — register to start earning →.

Checked by Gittensory, a quiet PR intelligence layer for OSS maintainers.

  • Re-run Gittensory review

@gittensory-orb gittensory-orb Bot added the gittensor Gittensor contributor context label Jun 27, 2026
@JSONbored JSONbored merged commit 207aa32 into main Jun 27, 2026
19 checks passed
@JSONbored JSONbored deleted the codex/fix-inline-review-posting-authorization-issue branch June 27, 2026 00:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

aardvark codex gittensor:bug Gittensor-scored bug fix - worth 0.5x multiplier. gittensor Gittensor contributor context size:S This PR changes 10-29 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant